gitlab vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the gitlab package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Incorrect Type Conversion or Cast

*
  • M
Resource Exhaustion

*
  • M
Improper Authentication

*
  • M
CVE-2020-13294

*
  • M
Improper Preservation of Permissions

*
  • M
CVE-2020-13290

*
  • M
Incorrect Authorization

*
  • M
Directory Traversal

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • L
Missing Authentication for Critical Function

*
  • M
CVE-2020-10074

*
  • M
Incorrect Authorization

*
  • M
CVE-2019-15592

*
  • M
Improper Authentication

*
  • L
Information Exposure

*
  • M
Incorrect Authorization

*
  • M
CVE-2019-15589

*
  • L
CVE-2019-19260

*
  • L
Information Exposure

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • L
Information Exposure

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • M
CVE-2019-15737

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Information Exposure

*
  • M
Information Exposure

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
Missing Authorization

*
  • M
CVE-2019-13010

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
CVE-2019-12428

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • L
CVE-2019-5883

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Authorization Bypass Through User-Controlled Key

*
  • L
Information Exposure

*
  • M
Arbitrary Command Injection

*
  • L
Authorization Bypass Through User-Controlled Key

*
  • M
Improper Input Validation

*
  • M
Information Exposure

*
  • M
CVE-2019-6788

*
  • L
Improper Privilege Management

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Privilege Management

*
  • M
Open Redirect

*
  • M
CVE-2019-6785

*
  • L
CVE-2019-6795

*
  • M
Incorrect Authorization

*
  • L
Improper Input Validation

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure Through Log Files

*
  • M
Information Exposure

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Information Exposure

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
CVE-2018-15472

*
  • M
Information Exposure Through Log Files

*
  • M
Information Exposure

*
  • M
Cross-site Request Forgery (CSRF)

*
  • M
Missing Authentication for Critical Function

*
  • L
Weak Password Recovery Mechanism for Forgotten Password

*
  • M
Cross-site Scripting (XSS)

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Input Validation

*
  • M
Directory Traversal

*
  • L
Cleartext Transmission of Sensitive Information

*
  • M
Improper Input Validation

*
  • M
Access Restriction Bypass

*