CVE-2019-19257
https://notcve.org/view.php?id=CVE-2019-19257
03 Jan 2020 — GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). GitLab Community Edition (CE) and Enterprise Edition (EE) versiones hasta la versión 12.5, tienen un Control de Acceso Incorrecto • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released •
CVE-2019-19256
https://notcve.org/view.php?id=CVE-2019-19256
03 Jan 2020 — GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control. GitLab Enterprise Edition (EE) versiones 12.2 y posteriores hasta la versión 12.5, tienen un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-19255
https://notcve.org/view.php?id=CVE-2019-19255
03 Jan 2020 — GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control. GitLab Enterprise Edition (EE) versiones 12.3 y posteriores hasta la versión 12.5, tiene un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released •
CVE-2019-19254
https://notcve.org/view.php?id=CVE-2019-19254
03 Jan 2020 — GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control. GitLab Community Edition (CE) and Enterprise Edition (EE). Versiones 9.6 y posteriores hasta la versión 12.5, tiene un Control de Acceso Incorrecto. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-19088
https://notcve.org/view.php?id=CVE-2019-19088
03 Jan 2020 — Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. Gitlab Enterprise Edition (EE) versiones 11.3 hasta la versión 12.4.2, permite un Salto de Directorio. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2019-19087
https://notcve.org/view.php?id=CVE-2019-19087
03 Jan 2020 — Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). Gitlab Enterprise Edition (EE) versiones anteriores a la versión 12.5.1, tiene Permisos No Seguros • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2019-19086
https://notcve.org/view.php?id=CVE-2019-19086
03 Jan 2020 — Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). Gitlab Enterprise Edition (EE) versiones anteriores a la versíon 12.5.1, tiene Permisos No Seguros (problema 1 de 2). • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2019-19311
https://notcve.org/view.php?id=CVE-2019-19311
03 Jan 2020 — GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields. GitLab EE versiones 8.14 hasta la versión 12.5, 12.4.3 y 12.3.6, permite un ataque de tipo XSS en los campos group y profile. • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-15584
https://notcve.org/view.php?id=CVE-2019-15584
20 Dec 2019 — A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. Se presenta una denegación de servicio en gitlab versiones anteriores a v12.3.2, versiones anteriores a v12.2.6 y versiones anteriores a v12.1.10, que permitiría a un atacante omitir la comprobación de entrada en los campos markdown para suspender la página afectada. • https://hackerone.com/reports/670572 • CWE-400: Uncontrolled Resource Consumption •
CVE-2019-15589
https://notcve.org/view.php?id=CVE-2019-15589
18 Dec 2019 — An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. Se presenta una vulnerabilidad de control de acceso inapropiado en Gitlab versiones anteriores a v12.3.2, versiones anteriores a v12.2.6, versiones anteriores a v12.1.12, que permitiría que un usuario bloqueado pudiera ser capaz de usar el clon GIT y extraer si hubiera obtenido un token CI/CD antes. • https://hackerone.com/reports/497047 • CWE-284: Improper Access Control •