
CVE-2019-18449
https://notcve.org/view.php?id=CVE-2019-18449
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2). Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad autocomplete. Posee Permisos No Seguros (problema 2 de 2). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18450
https://notcve.org/view.php?id=CVE-2019-18450
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions. Se detectó un problema en GitLab Community and Enterprise Edition versiones anteriores a 12.4, en la funcionalidad Project labels. Posee Permisos No Seguros. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18451
https://notcve.org/view.php?id=CVE-2019-18451
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect. Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.7.4 hasta 12.4, en la funcionalidad InternalRedirect filtering. Posee un Redireccionamiento Abierto. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2019-18454
https://notcve.org/view.php?id=CVE-2019-18454
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS. Se detectó un problema en GitLab Community and Enterprise Edition versiones 10.5 hasta 12.4, en la comprobación de enlaces para la funcionalidad de páginas RDoc wiki. Presenta una vulnerabilidad de tipo XSS. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-18455
https://notcve.org/view.php?id=CVE-2019-18455
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop. Se detectó un problema en GitLab Community and Enterprise Edition versiones 11 hasta 12.4, cuando se construyen consultas GraphQL anidadas. Posee un bucle grande o infinito. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2019-18456
https://notcve.org/view.php?id=CVE-2019-18456
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4). Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.17 hasta 12.4, en la funcionalidad Search provista por la integración de Elasticsearch. Posee Permisos No Seguros (problema 1 de 4). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-18458
https://notcve.org/view.php?id=CVE-2019-18458
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4). Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.4. Posee Permisos No Seguros (problema 2 de 4). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-281: Improper Preservation of Permissions •

CVE-2019-18460
https://notcve.org/view.php?id=CVE-2019-18460
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control. Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.15 hasta 12.4, en la funcionalidad Comments Search provista por la integración de Elasticsearch. Posee un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-18463
https://notcve.org/view.php?id=CVE-2019-18463
26 Nov 2019 — An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4). Se detectó un problema en GitLab Community and Enterprise Edition versiones hasta 12.4. Posee Permisos No Seguros (problema 4 de 4). • https://about.gitlab.com/blog/2019/10/30/security-release-gitlab-12-dot-4-dot-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-15729
https://notcve.org/view.php?id=CVE-2019-15729
17 Sep 2019 — An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request. Se detectó un problema en GitLab Community and Enterprise Edition versiones 8.18 hasta 12.2.1. Un end point interno divulgó involuntariamente información sobre la última pipeline que se ejecutó para una petición de fusión. • https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released • CWE-863: Incorrect Authorization •