Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
CVE-2019-7176 vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2019-7155
An issue exists in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, i...
Gitlab Gitlab
7.5
CVSSv3
CVE-2019-6781
An Improper Input Validation issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.
Gitlab Gitlab
8.8
CVSSv3
CVE-2019-6783
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.
Gitlab Gitlab
6.5
CVSSv3
CVE-2019-6786
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are know...
Gitlab Gitlab
4.3
CVSSv3
CVE-2019-6790
An Incorrect Access Control (issue 2 of 3) issue exists in GitLab Community and Enterprise Edition 8.14 and later but prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. Guest users were able to view the list of a group's merge requests.
Gitlab Gitlab
6.5
CVSSv3
CVE-2019-6787
An Incorrect Access Control issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.
Gitlab Gitlab
5.4
CVSSv3
CVE-2019-6795
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be use...
Gitlab Gitlab
4.3
CVSSv3
CVE-2019-6794
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.
Gitlab Gitlab
6.1
CVSSv3
CVE-2019-6796
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS.
Gitlab Gitlab
7.5
CVSSv3
CVE-2019-6788
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect...
Gitlab Gitlab
2 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2