|
223441
|
5.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private p…
|
NVD-CWE-noinfo
|
CVE-2019-19312
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223442
|
4.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19310
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223443
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-19309
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223444
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19263
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223445
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19262
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223446
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-19261
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223447
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
|
NVD-CWE-noinfo
|
CVE-2019-19260
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223448
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-19259
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223449
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-19258
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223450
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
|
NVD-CWE-noinfo
|
CVE-2019-19257
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|