Debian Gitlab vulnerabilities

1,325 known vulnerabilities affecting debian/gitlab.

Total CVEs
1,325
CISA KEV
4
actively exploited
Public exploits
22
Exploited in wild
2
Severity breakdown
CRITICAL43HIGH196MEDIUM630LOW456

Vulnerabilities

Page 54 of 67
CVE-2019-15726MEDIUMCVSS 5.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15726 [MEDIUM] CVE-2019-15726: gitlab - An issue was discovered in GitLab Community and Enterprise Edition through 12.2.... An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-19254MEDIUMCVSS 5.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-19254 [MEDIUM] CVE-2019-19254: gitlab - GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through... GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-7549MEDIUMCVSS 4.3fixed in gitlab 11.5.10+dfsg-1 (sid)2019
CVE-2019-7549 [MEDIUM] CVE-2019-7549: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x... An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information. Scope: local sid: resolved (fixed in 11.5.10+dfsg-1)
debian
CVE-2019-15581MEDIUMCVSS 5.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15581 [MEDIUM] CVE-2019-15581: gitlab - An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition... An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-15592MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15592 [MEDIUM] CVE-2019-15592: gitlab - GitLab 12.2.2 and below contains a security vulnerability that allows a guest us... GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-18453MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-18453 [MEDIUM] CVE-2019-18453: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 11.6 through ... An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-9178MEDIUMCVSS 5.3fixed in gitlab 11.8.2-2 (sid)2019
CVE-2019-9178 [MEDIUM] CVE-2019-9178: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.6.1... An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 4 of 5). Scope: local sid: resolved (fixed in 11.8.2-2)
debian
CVE-2019-12444MEDIUMCVSS 6.1fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12444 [MEDIUM] CVE-2019-12444: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 1... An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-15579MEDIUMCVSS 5.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15579 [MEDIUM] CVE-2019-15579: gitlab - An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab... An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-13006MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-13006 [MEDIUM] CVE-2019-13006: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 9.0 and throu... An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-15733MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15733 [MEDIUM] CVE-2019-15733: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 7.12 through ... An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-12431MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12431 [MEDIUM] CVE-2019-12431: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.13 through ... An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-6790MEDIUMCVSS 4.3fixed in gitlab 11.5.10+dfsg-1 (sid)2019
CVE-2019-6790 [MEDIUM] CVE-2019-6790: gitlab - An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Commun... An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests. Scope: local sid: resolved (fixed in 11.5.10+dfsg-1)
debian
CVE-2019-15591MEDIUMCVSS 6.5fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-15591 [MEDIUM] CVE-2019-15591: gitlab - An improper access control vulnerability exists in GitLab <12.3.3 that allows an... An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-20147MEDIUMCVSS 5.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-20147 [MEDIUM] CVE-2019-20147: gitlab - An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition ... An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-9866MEDIUMCVSS 6.5fixed in gitlab 11.8.3-1 (sid)2019
CVE-2019-9866 [MEDIUM] CVE-2019-9866: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 11.x before 1... An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure. Scope: local sid: resolved (fixed in 11.8.3-1)
debian
CVE-2019-6796MEDIUMCVSS 6.1fixed in gitlab 11.5.10+dfsg-1 (sid)2019
CVE-2019-6796 [MEDIUM] CVE-2019-6796: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8... An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS. Scope: local sid: resolved (fixed in 11.5.10+dfsg-1)
debian
CVE-2019-12432MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12432 [MEDIUM] CVE-2019-12432: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.13 through ... An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-12434MEDIUMCVSS 4.3fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12434 [MEDIUM] CVE-2019-12434: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 10.6 through ... An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure. Scope: local sid: resolved (fixed in 12.6.8-3)
debian
CVE-2019-12445MEDIUMCVSS 5.4fixed in gitlab 12.6.8-3 (sid)2019
CVE-2019-12445 [MEDIUM] CVE-2019-12445: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 1... An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS. Scope: local sid: resolved (fixed in 12.6.8-3)
debian