CVE-2018-19493
https://notcve.org/view.php?id=CVE-2018-19493
10 Jul 2019 — An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding. Se descubrió un problema en Community and Enterprise Edition versiones 11.x anteriores a 11.3.11, versiones 11.4.x anteriores a 11.4.8 y versiones 11.5.x anteriores a 11.5.1 de GitLab. Se presenta una vulnerabilidad de tipo XSS persistente en las páginas d... • http://www.securityfocus.com/bid/109122 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-9866
https://notcve.org/view.php?id=CVE-2019-9866
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure. Fue encontrado un problema en GitLab Community and Enterprise Edition versión 11.x anterior a 11.7.7 y versión 11.8.x anterior a 11.8.3. Esta permite la divulgación de información. • https://about.gitlab.com/2019/03/20/critical-security-release-gitlab-11-dot-8-dot-3-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-9732
https://notcve.org/view.php?id=CVE-2019-9732
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control. Fue encontrado un problema en GitLab Community and Enterprise Edition versión 10.x (a partir de 10.8) y versión 11.x anteriores a 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta un control de acceso incorrecto. • https://about.gitlab.com/2019/03/14/gitlab-11-8-2-released •
CVE-2019-9485
https://notcve.org/view.php?id=CVE-2019-9485
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions. Fue encontrado un problema en GitLab Community and Enterprise Edition anteriores a la versión 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta permisos no seguros. • https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released •
CVE-2019-9221
https://notcve.org/view.php?id=CVE-2019-9221
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5). Fue encontrado un problema en GitLab Community and Enterprise Edition anterior a la versión 11.6.10, versión 11.7.x anteriores a 11.7.6 y versión 11.8.x anteriores a 11.8.1. Presenta un control de acceso incorrecto (problema 3 de 5). • https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released • CWE-20: Improper Input Validation •
CVE-2019-9218
https://notcve.org/view.php?id=CVE-2019-9218
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5). Fue encontrado un problema en GitLab Community and Enterprise Edition versión anterior de 11.6.10, versión 11.7.x anterior de 11.7.6 y versión 11.8.x anterior de 11.8.1. Tiene control de acceso incorrecto (problema 1 de 5). • https://about.gitlab.com/blog/categories/releases •
CVE-2019-7549
https://notcve.org/view.php?id=CVE-2019-7549
29 May 2019 — An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information. Se detecto un problema en GitLab Community and Enterprise Edition versiones 10.x y 11.x en versiones anteriores a la 11.5.10, versión 11.6.x en versiones anteriores a la 11.6.8, y versión 11.7.x en versiones ante... • https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released •
CVE-2019-6797
https://notcve.org/view.php?id=CVE-2019-6797
17 May 2019 — An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI. Se descubrió un problema de divulgación de información en GitLab Enterprise Edition antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. El token de GitHub utilizado en CI/CD para reposiciones externas se estaba filtrando a los mantenedores del proyecto en la... • https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released •
CVE-2019-6790
https://notcve.org/view.php?id=CVE-2019-6790
17 May 2019 — An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests. Se detectó un problema de control de acceso incorrecto (problema 2 de 3) en GitLab Community and Enterprise Edition 8.14 y versiones posteriores, pero antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. Los usuarios invitados pudieron ver la... • https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released • CWE-862: Missing Authorization •
CVE-2019-6787
https://notcve.org/view.php?id=CVE-2019-6787
17 May 2019 — An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users. Se descubrió un problema de control de acceso incorrecto en GitLab Community and Enterprise Edition antes de 11.5.8, 11.6.x antes de 11.6.6 y 11.7.x antes de 11.7.1. La API de GitLab permitió a los mantenedores y propietarios del proyecto ver los token... • https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released •