CVE-2020-7978
https://notcve.org/view.php?id=CVE-2020-7978
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service. GitLab EE versiones 12.6 y posteriores hasta 12.7.2, permiten una Denegación de Servicio. • https://about.gitlab.com/blog/categories/releases https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released •
CVE-2020-7979
https://notcve.org/view.php?id=CVE-2020-7979
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros. • https://about.gitlab.com/blog/categories/releases https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released • CWE-276: Incorrect Default Permissions •
CVE-2020-8114
https://notcve.org/view.php?id=CVE-2020-8114
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab EE versiones 8.9 y posteriores hasta 12.7.2, presenta Permisos No Seguros. • https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released https://about.gitlab.com/releases/categories/releases https://gitlab.com/gitlab-org/gitlab/issues/37468 • CWE-276: Incorrect Default Permissions •
CVE-2019-15590
https://notcve.org/view.php?id=CVE-2019-15590
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration Se presenta un problema de control de acceso en versiones anteriores a 12.3.5, versiones anteriores a 12.2.8 y versiones anteriores a 12.1.14 para GitLab Community Edition (CE) y Enterprise Edition (EE), donde las peticiones y problemas de fusión privada serían divulgados con la funcionalidad Group Search proporcionada por la integración Elasticsearch. • https://about.gitlab.com/releases/2019/10/07/security-release-gitlab-12-dot-3-dot-5-released https://hackerone.com/reports/701144 • CWE-284: Improper Access Control •
CVE-2019-20142
https://notcve.org/view.php?id=CVE-2019-20142
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service. Se descubrió un problema en GitLab Community Edition (CE) and Enterprise Edition (EE) versiones 12.3 hasta la versión 12.6.1. Permite una Denegación de Servicio. • https://about.gitlab.com/blog/categories/releases https://about.gitlab.com/releases/2020/01/02/security-release-gitlab-12-6-2-released •