
CVE-2019-15579
https://notcve.org/view.php?id=CVE-2019-15579
28 Jan 2020 — An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones. Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde el o los cesionarios de un problema confidencial en un proy... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-5468
https://notcve.org/view.php?id=CVE-2019-5468
28 Jan 2020 — An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account. Se detectó un problema de escalada de privilegios en GitLab versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, cuando los comandos de barra de Mattermost son usados con una cuenta bloqueada. • https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released • CWE-269: Improper Privilege Management •

CVE-2019-15581
https://notcve.org/view.php?id=CVE-2019-15581
28 Jan 2020 — An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules. Se presenta un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió al propietario o mantenedor del proyecto visualizar a los miembros de cualquier grupo pri... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2019-15582
https://notcve.org/view.php?id=CVE-2019-15582
28 Jan 2020 — An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment. Se detectó un IDOR en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), que permitió a un mantenedor agregar cualquier grupo privado a un entorno protegido. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2019-15590
https://notcve.org/view.php?id=CVE-2019-15590
28 Jan 2020 — An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration Se presenta un problema de control de acceso en versiones anteriores a 12.3.5, versiones anteriores a 12.2.8 y versiones anteriores a 12.1.14 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde las peticiones y problemas de fusión privada ... • https://about.gitlab.com/releases/2019/10/07/security-release-gitlab-12-dot-3-dot-5-released • CWE-284: Improper Access Control •

CVE-2019-5474
https://notcve.org/view.php?id=CVE-2019-5474
28 Jan 2020 — An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. Se detectó un problema de autorización en GitLab EE versiones anteriores a 12.1.2, versiones anteriores a 12.0.4 y versiones anteriores a 11.11.6, permitiendo que las reglas de aprobación de petición de fusión sea anuladas sin los permisos apropiados. • https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2019-15583
https://notcve.org/view.php?id=CVE-2019-15583
28 Jan 2020 — An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API. Se presenta una divulgación de información en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE). Cuando... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-15585
https://notcve.org/view.php?id=CVE-2019-15585
28 Jan 2020 — Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account. Se presenta una autenticación inapropiada en versiones anteriores a 12.3.2, versiones anteriores a 12.2.6 y versiones anteriores a 12.1.12 para GitLab Community Edition (CE) y Enterprise Edition (EE), en la integración GitLab SAML se presenta un problema de comprob... • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-287: Improper Authentication •

CVE-2019-15586
https://notcve.org/view.php?id=CVE-2019-15586
28 Jan 2020 — A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. Se presenta una vulnerabilidad de tipo XSS en Gitlab CE/EE versiones anteriores a 12.1.10, en el complemento Mermaid. • https://about.gitlab.com/blog/2019/09/30/security-release-gitlab-12-dot-3-dot-2-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-20142
https://notcve.org/view.php?id=CVE-2019-20142
13 Jan 2020 — An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service. Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 12.3 hasta la versión 12.6.1. Permite una Denegación de Servicio. • https://about.gitlab.com/blog/categories/releases •