CVE-2020-12448
https://notcve.org/view.php?id=CVE-2020-12448
07 May 2020 — GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. GitLab EE versión 12.8 y posterior, permite una Exposición de Información Confidencial a un Actor No Autorizado por medio de NuGet. • https://about.gitlab.com/blog/categories/releases • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-12275
https://notcve.org/view.php?id=CVE-2020-12275
29 Apr 2020 — GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API. GitLab versiones 12.6 hasta 12.9 es vulnerable a una escalada de privilegios que permite a un usuario externo crear un fragmento personal por medio de la API. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •
CVE-2020-12276
https://notcve.org/view.php?id=CVE-2020-12276
29 Apr 2020 — GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature. GitLab versiones 9.5.9 hasta 12.9, es vulnerable a un ataque de tipo XSS almacenado en una funcionalidad de notificación de administrador. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-12277
https://notcve.org/view.php?id=CVE-2020-12277
29 Apr 2020 — GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated. GitLab versiones 10.8 hasta 12.9, tiene una vulnerabilidad que permite a alguien reflejar un repositorio incluso si la función no está activada. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-276: Incorrect Default Permissions •
CVE-2020-11649
https://notcve.org/view.php?id=CVE-2020-11649
22 Apr 2020 — An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted. Se descubrió un problema en GitLab CE and EE versiones 8.15 hasta la versión 12.9.2. Los miembros de un grupo aún podrían tener acceso después de que se elimine el grupo. • https://about.gitlab.com/blog/categories/releases • CWE-306: Missing Authentication for Critical Function •
CVE-2020-11506
https://notcve.org/view.php?id=CVE-2020-11506
22 Apr 2020 — An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling. Se descubrió un problema en GitLab versiones 10.7.0 y posteriores hasta la versión 12.9.2. Una omisión de Workhorse podría conllevar a una carga de artefactos de trabajo y una divulgación de archivos (Exposición de información confidencial) por medio del tráfico no autorizado de peticiones. • https://about.gitlab.com/blog/categories/releases • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •
CVE-2020-11505
https://notcve.org/view.php?id=CVE-2020-11505
22 Apr 2020 — An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling. Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones anteriores a la versión 12.7.9, versiones 12.8.x anteriores a la versión 12.8.9 y versiones 12.9.x anteriores a la versión 12.9.3. Una omisión... • https://about.gitlab.com/blog/categories/releases • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •
CVE-2020-10975
https://notcve.org/view.php?id=CVE-2020-10975
08 Apr 2020 — GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page. GitLab EE/CE versiones 10.8 hasta 12.9, está filtrando metadatos y comentarios sobre vulnerabilidades a usuarios no autorizados en la página de comentarios sobre vulnerabilidades. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released •
CVE-2020-10976
https://notcve.org/view.php?id=CVE-2020-10976
08 Apr 2020 — GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget. GitLab EE/CE versiones 8.17 hasta 12.9, es vulnerable a la filtrado de información al consultar un widget de una petición de fusión. • https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2020-10977 – GitLab File Read Remote Code Execution
https://notcve.org/view.php?id=CVE-2020-10977
08 Apr 2020 — GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. GitLab EE/CE versiones 8.5 hasta 12.9, es vulnerable a un salto de ruta cuando se mueve un problema entre proyectos. • https://github.com/KooroshRZ/CVE-2020-10977 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •