Debian Gitlab vulnerabilities
1,325 known vulnerabilities affecting debian/gitlab.
Total CVEs
1,325
CISA KEV
4
actively exploited
Public exploits
22
Exploited in wild
2
Severity breakdown
CRITICAL43HIGH196MEDIUM630LOW456
Vulnerabilities
Page 64 of 67
CVE-2018-17453MEDIUMCVSS 5.3fixed in gitlab 11.1.8+dfsg-2 (sid)2018
CVE-2018-17453 [MEDIUM] CVE-2018-17453: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7...
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception.
Scope: local
sid: resolved (fixed in 11.1.8+dfsg-2)
debian
CVE-2018-17536MEDIUMCVSS 5.4fixed in gitlab 11.1.8+dfsg-2 (sid)2018
CVE-2018-17536 [MEDIUM] CVE-2018-17536: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7...
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.
Scope: local
sid: resolved (fixed in 11.1.8+dfsg-2)
debian
CVE-2018-20498MEDIUMCVSS 4.3fixed in gitlab 11.5.6+dfsg-1 (sid)2018
CVE-2018-20498 [MEDIUM] CVE-2018-20498: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.4.1...
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Scope: local
sid: resolved (fixed in 11.5.6+dfsg-1)
debian
CVE-2018-19496MEDIUMCVSS 6.5fixed in gitlab 11.3.11+dfsg-1 (sid)2018
CVE-2018-19496 [MEDIUM] CVE-2018-19496: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x...
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.
Scope: local
sid: resolved (fixed in 11.3.11+dfsg-1)
debian
CVE-2018-19570MEDIUMCVSS 5.4fixed in gitlab 11.3.11+dfsg-1 (sid)2018
CVE-2018-19570 [MEDIUM] CVE-2018-19570: gitlab - GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before ...
GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.
Scope: local
sid: resolved (fixed in 11.3.11+dfsg-1)
debian
CVE-2018-20491MEDIUMCVSS 5.4fixed in gitlab 11.5.6+dfsg-1 (sid)2018
CVE-2018-20491 [MEDIUM] CVE-2018-20491: gitlab - An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11...
An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Scope: local
sid: resolved (fixed in 11.5.6+dfsg-1)
debian
CVE-2018-14605MEDIUMCVSS 5.4fixed in gitlab 10.8.7+dfsg-1 (sid)2018
CVE-2018-14605 [MEDIUM] CVE-2018-14605: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7...
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.
Scope: local
sid: resolved (fixed in 10.8.7+dfsg-1)
debian
CVE-2018-18645MEDIUMCVSS 4.3fixed in gitlab 11.2.8+dfsg-2 (sid)2018
CVE-2018-18645 [MEDIUM] CVE-2018-18645: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7...
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.
Scope: local
sid: resolved (fixed in 11.2.8+dfsg-2)
debian
CVE-2018-17450MEDIUMCVSS 4.3fixed in gitlab 11.1.8+dfsg-2 (sid)2018
CVE-2018-17450 [MEDIUM] CVE-2018-17450: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7...
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.
Scope: local
sid: resolved (fixed in 11.1.8+dfsg-2)
debian
CVE-2018-19575MEDIUMCVSS 4.3fixed in gitlab 11.3.11+dfsg-1 (sid)2018
CVE-2018-19575 [MEDIUM] CVE-2018-19575: gitlab - GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 1...
GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.
Scope: local
sid: resolved (fixed in 11.3.11+dfsg-1)
debian
CVE-2018-19573MEDIUMCVSS 5.4fixed in gitlab 11.3.11+dfsg-1 (sid)2018
CVE-2018-19573 [MEDIUM] CVE-2018-19573: gitlab - GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 1...
GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.
Scope: local
sid: resolved (fixed in 11.3.11+dfsg-1)
debian
CVE-2018-12607MEDIUMCVSS 5.4fixed in gitlab 10.7.7+dfsg-2 (sid)2018
CVE-2018-12607 [MEDIUM] CVE-2018-12607: gitlab - An issue was discovered in GitLab Community Edition and Enterprise Edition befor...
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.
Scope: local
sid: resolved (fixed in 10.7.7+dfsg-2)
debian
CVE-2018-12605MEDIUMCVSS 5.4fixed in gitlab 10.7.7+dfsg-2 (sid)2018
CVE-2018-12605 [MEDIUM] CVE-2018-12605: gitlab - An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7....
An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.
Scope: local
sid: resolved (fixed in 10.7.7+dfsg-2)
debian
CVE-2018-19577MEDIUMCVSS 5.3fixed in gitlab 11.3.11+dfsg-1 (sid)2018
CVE-2018-19577 [MEDIUM] CVE-2018-19577: gitlab - Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11...
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
Scope: local
sid: resolved (fixed in 11.3.11+dfsg-1)
debian
CVE-2018-16051MEDIUMCVSS 6.5fixed in gitlab 11.1.8+dfsg-2 (sid)2018
CVE-2018-16051 [MEDIUM] CVE-2018-16051: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6...
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.
Scope: local
sid: resolved (fixed in 11.1.8+dfsg-2)
debian
CVE-2018-20496MEDIUMCVSS 5.4fixed in gitlab 11.5.6+dfsg-1 (sid)2018
CVE-2018-20496 [MEDIUM] CVE-2018-20496: gitlab - An issue was discovered in GitLab Community and Enterprise Edition 11.2.x throug...
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Scope: local
sid: resolved (fixed in 11.5.6+dfsg-1)
debian
CVE-2018-17537MEDIUMCVSS 5.4fixed in gitlab 11.1.8+dfsg-2 (sid)2018
CVE-2018-17537 [MEDIUM] CVE-2018-17537: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7...
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. .
Scope: local
sid: resolved (fixed in 11.1.8+dfsg-2)
debian
CVE-2018-9243MEDIUMCVSS 6.1fixed in gitlab 10.6.3+dfsg-1 (sid)2018
CVE-2018-9243 [MEDIUM] CVE-2018-9243: gitlab - GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable t...
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
Scope: local
sid: resolved (fixed in 10.6.3+dfsg-1)
debian
CVE-2018-20489MEDIUMCVSS 5.3fixed in gitlab 11.5.6+dfsg-1 (sid)2018
CVE-2018-20489 [MEDIUM] CVE-2018-20489: gitlab - An issue was discovered in GitLab Community and Enterprise Edition before 11.4.1...
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Scope: local
sid: resolved (fixed in 11.5.6+dfsg-1)
debian
CVE-2018-18843LOWCVSS 10.02018
CVE-2018-18843 [CRITICAL] CVE-2018-18843: gitlab - The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3...
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
Scope: local
sid: resolved
debian