
CVE-2020-10977 – GitLab File Read Remote Code Execution
https://notcve.org/view.php?id=CVE-2020-10977
08 Apr 2020 — GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. GitLab EE/CE versiones 8.5 hasta 12.9, es vulnerable a un salto de ruta cuando se mueve un problema entre proyectos. • https://packetstorm.news/files/id/160441 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-10978
https://notcve.org/view.php?id=CVE-2020-10978
08 Apr 2020 — GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API. GitLab EE/CE versiones 8.11 hasta 12.9, está filtrando información sobre Problemas aperturados en un proyecto público y luego es movido a un proyecto privado por medio de Interfaz de Usuario Web y la API GraphQL. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •

CVE-2020-10979
https://notcve.org/view.php?id=CVE-2020-10979
08 Apr 2020 — GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users. GitLab EE/CE versiones 11.10 hasta 12.9, está filtrando información sobre métricas de tuberías de CI a usuarios no autorizados. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •

CVE-2020-10980
https://notcve.org/view.php?id=CVE-2020-10980
08 Apr 2020 — GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. GitLab EE/CE versiones 8.0.rc1 hasta 12.9, es vulnerable a un ataque de tipo SSRF ciego en la integración de FogBugz. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2020-10981
https://notcve.org/view.php?id=CVE-2020-10981
08 Apr 2020 — GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project. GitLab EE/CE versiones 9.0 hasta 12.9, permite a un mantenedor modificar las descripciones de activación de la tubería de otros mantenedores dentro del mismo proyecto. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •

CVE-2020-10952
https://notcve.org/view.php?id=CVE-2020-10952
27 Mar 2020 — GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. GitLab EE/CE versiones 8.11 hasta 12.9.1, permite a usuarios bloqueados extraer y empujar imágenes de docker. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •

CVE-2020-10953
https://notcve.org/view.php?id=CVE-2020-10953
27 Mar 2020 — In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. En GitLab EE versiones 11.7 hasta 12.9, la funcionalidad NPM es vulnerable a un problema de salto de ruta. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-10954
https://notcve.org/view.php?id=CVE-2020-10954
27 Mar 2020 — GitLab through 12.9 is affected by a potential DoS in repository archive download. GitLab versiones hasta 12.9, está afectado por una DoS potencial en una descarga de archivo del repositorio. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-400: Uncontrolled Resource Consumption •

CVE-2020-10955 – Debian Security Advisory 4691-1
https://notcve.org/view.php?id=CVE-2020-10955
27 Mar 2020 — GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. GitLab EE/CE versiones 11.1 hasta 12.9, es vulnerable a una manipulación de parámetros en una funcionalidad de carga que permite a un usuario no autorizado leer el contenido disponible bajo carpetas específicas. Two vulnerabiliites have been discovered in PDNS Recursor, a resolving name server; a traffic amplification attack against third... • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-862: Missing Authorization •

CVE-2020-10956
https://notcve.org/view.php?id=CVE-2020-10956
27 Mar 2020 — GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. GitLab versiones 8.10 y posteriores a 12.9, es vulnerable a un ataque de tipo SSRF en una funcionalidad de nota de importación de proyecto. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-918: Server-Side Request Forgery (SSRF) •