CVE-2018-17976
https://notcve.org/view.php?id=CVE-2018-17976
04 Dec 2018 — An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions. Se ha descubierto un problema en la edición Community de GitLab, en versiones 11.1.x anteriores a la 11.1.8, versiones 11.2.x anteriores a la 11.2.5 y versiones 11.3.x anteriores a la 11.3.2. Hay una exposición de información mediante las descripciones de cambios Epic. • https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-17939
https://notcve.org/view.php?id=CVE-2018-17939
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 11.1.x anteriores a la 11.1.8, versiones 11.2.x anteriores a la 11.2.5 y versiones 11.3.x anteriores a la 11.3.2. Hay una exposición de información mediante el endpoint de petición JSON "merge". • https://about.gitlab.com/2018/10/05/critical-security-release-11-3-4 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-18645
https://notcve.org/view.php?id=CVE-2018-18645
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite la exposición de información mediante los enlaces de desuscripción en las respuestas de emails. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-18640
https://notcve.org/view.php?id=CVE-2018-18640
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una exposición de información mediante el cacheo del navegador. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-18642
https://notcve.org/view.php?id=CVE-2018-18642
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene Cross-Site Scripting (XSS). • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-18644
https://notcve.org/view.php?id=CVE-2018-18644
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones 11.x anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite la exposición de información mediante la integración con Gitlab Prometheus. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-18641
https://notcve.org/view.php?id=CVE-2018-18641
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene almacenamiento en texto claro de información sensible. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2018-18648
https://notcve.org/view.php?id=CVE-2018-18648
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una exposición de información mediante un mensaje de error. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-18646
https://notcve.org/view.php?id=CVE-2018-18646
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Permite Server-Side Request Forgery (SSRF). • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2018-18647
https://notcve.org/view.php?id=CVE-2018-18647
04 Dec 2018 — An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Missing Authorization. Se ha descubierto un problema en las ediciones Community y Enterprise de GitLab, en versiones anteriores a la 11.2.7, versiones 11.3.x anteriores a la 11.3.8 y versiones 11.4.x anteriores a la 11.4.3. Tiene una falta de autorización. • https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released • CWE-862: Missing Authorization •