CVE-2020-7972
https://notcve.org/view.php?id=CVE-2020-7972
05 Feb 2020 — GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). GitLab EE versión 12.2, presenta Permisos No Seguros (problema 2 de 2). • https://about.gitlab.com/blog/categories/releases • CWE-276: Incorrect Default Permissions •
CVE-2020-7973
https://notcve.org/view.php?id=CVE-2020-7973
05 Feb 2020 — GitLab through 12.7.2 allows XSS. GitLab versiones hasta 12.7.2, permite un ataque de tipo XSS. • https://about.gitlab.com/blog/categories/releases • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-7974
https://notcve.org/view.php?id=CVE-2020-7974
05 Feb 2020 — GitLab EE 10.1 through 12.7.2 allows Information Disclosure. GitLab EE versiones 10.1 hasta 12.7.2, permite una Divulgación de Información. • https://about.gitlab.com/blog/categories/releases •
CVE-2020-7977
https://notcve.org/view.php?id=CVE-2020-7977
05 Feb 2020 — GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. GitLab EE versiones 8.8 y posteriores hasta 12.7.2, presenta Permisos No Seguros. • https://about.gitlab.com/blog/categories/releases • CWE-276: Incorrect Default Permissions •
CVE-2020-7979
https://notcve.org/view.php?id=CVE-2020-7979
05 Feb 2020 — GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros. • https://about.gitlab.com/blog/categories/releases • CWE-276: Incorrect Default Permissions •
CVE-2020-8114
https://notcve.org/view.php?id=CVE-2020-8114
05 Feb 2020 — GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros. • https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released • CWE-276: Incorrect Default Permissions •
CVE-2019-15578
https://notcve.org/view.php?id=CVE-2019-15578
28 Jan 2020 — An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests. Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE). La ruta de un proyecto privado, que solía s... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-15579
https://notcve.org/view.php?id=CVE-2019-15579
28 Jan 2020 — An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones. Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde el o los cesionarios de un problema confidencial en un proy... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-15581
https://notcve.org/view.php?id=CVE-2019-15581
28 Jan 2020 — An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules. Se presenta un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió al propietario o mantenedor del proyecto visualizar a los miembros de cualquier grupo pri... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2019-15582
https://notcve.org/view.php?id=CVE-2019-15582
28 Jan 2020 — An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment. Se detectó un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió a un mantenedor agregar cualquier grupo privado a un entorno protegido. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-639: Authorization Bypass Through User-Controlled Key •