Versions
>=8.8.9
Affects GitLab CE/EE 10.2 and later
>=8.14
>=13.5 to <13.5.5
>= 13.5 to <13.5.5
>= 12.2 to <13.4.7
>=12.6
>= 13.1 to <13.4.7
>=13.0
>=13.4.0
>=13.5.0
>= 13.6 to <13.6.2
>=13.6, <13.6.2
>=12.10
Affects GitLab CE/EE 8.14 and later
>=13.6 to <13.6.2
>=10.3
>=12.8
>=13.4, <13.4.7
>=13.1 to <13.4.7
>=10.2
Fixed in 12.1.2 in 12.0.4 and in 11.11.6
>=13.5, <13.5.5
<13.5.5
<13.4.5
before 12.3.2
<13.6.2
<13.4.7
<13.3.9
>=12.4
>=13.5
<13.5.2
>=13.4
before 12.1.12
before 12.2.6
before 12.1.10
>=13.3
>=13.6
Recent CVEs
CVE-2020-26408
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
CVE-2020-13357
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.
CVE-2020-26413
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
CVE-2020-26417
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.
CVE-2020-26409
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
CVE-2020-26407
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
CVE-2020-26405
Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
CVE-2020-13352
Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.