
CVE-2019-5486
https://notcve.org/view.php?id=CVE-2019-5486
18 Dec 2019 — A authentication bypass vulnerability exists in GitLab CE/EE

CVE-2019-15591
https://notcve.org/view.php?id=CVE-2019-15591
18 Dec 2019 — An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. Se presenta una vulnerabilidad de control de acceso inapropiado en GitLab versiones anteriores a 12.3.3 lo que permite a un atacante obtener informes de escaneo de contenedores y dependencias por medio del widget de petición de fusión a pesar de que las tuberías públicas estaban deshabilitada... • https://hackerone.com/reports/676976 • CWE-284: Improper Access Control •

CVE-2019-18447
https://notcve.org/view.php?id=CVE-2019-18447
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions. Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4. Posee Permisos No Seguros. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18448
https://notcve.org/view.php?id=CVE-2019-18448
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control. Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4. Posee un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released •

CVE-2019-18449
https://notcve.org/view.php?id=CVE-2019-18449
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2). Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad autocomplete. Posee Permisos No Seguros (problema 2 de 2). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18450
https://notcve.org/view.php?id=CVE-2019-18450
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions. Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad Project labels. Posee Permisos No Seguros. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18463
https://notcve.org/view.php?id=CVE-2019-18463
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4). Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.4. Posee Permisos No Seguros (problema 4 de 4). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-15737
https://notcve.org/view.php?id=CVE-2019-15737
16 Sep 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management. Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Determinadas acciones de la cuenta necesitaban autenticación mejorada y administración de sesión. • https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released •

CVE-2019-15736
https://notcve.org/view.php?id=CVE-2019-15736
16 Sep 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack. Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Bajo ciertas circunstancias, las pipelines de CI podrían ser usadas potencialmente en un ataque de denegación de servicio. • https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2019-15726
https://notcve.org/view.php?id=CVE-2019-15726
16 Sep 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server. Se descubrió un problema en GitLab Community and Enterprise Edition versiones hasta 12.2.1. Las imágenes y los archivos multimedia insertados en Markdown podrían ser apuntados hacia un servidor arbitrario, que revelaría la dirección IP de los clientes que solic... • https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released •