Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
CVE-2019-7176 vulnerabilities and exploits
(subscribe to this query)
3.7
CVSSv3
CVE-2019-7176
An issue exists in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x prior to 11.5.9, 11.6.x prior to 11.6.7, and 11.7.x prior to 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have n...
Gitlab Gitlab
7.5
CVSSv3
CVE-2019-6782
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.
Gitlab Gitlab
6.1
CVSSv3
CVE-2019-6784
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent ...
Gitlab Gitlab
6.5
CVSSv3
CVE-2019-6787
An Incorrect Access Control issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.
Gitlab Gitlab
5.4
CVSSv3
CVE-2019-6795
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be use...
Gitlab Gitlab
9.8
CVSSv3
CVE-2019-6960
An issue exists in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.
Gitlab Gitlab
4.3
CVSSv3
CVE-2019-6997
An issue exists in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge r...
Gitlab Gitlab
7.5
CVSSv3
CVE-2019-6781
An Improper Input Validation issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.
Gitlab Gitlab
6.5
CVSSv3
CVE-2019-6785
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.
Gitlab Gitlab
4.3
CVSSv3
CVE-2019-6794
An issue exists in GitLab Community and Enterprise Edition prior to 11.5.8, 11.6.x prior to 11.6.6, and 11.7.x prior to 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.
Gitlab Gitlab
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4644
unprivileged
CVE-2024-3494
CVE-2024-22460
CVE-2024-26026
CVE-2024-23473
firewall
CVE-2024-28889
XML external entity
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »