Rapid7

vulnerability

FreeBSD: VID-4091069e-860b-11e9-a05f-001b217b3468 (CVE-2019-12445): Gitlab -- Multiple Vulnerabilities

Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Jun 3, 2019
Added
Jun 3, 2019
Modified
Mar 25, 2026

Description

Gitlab reports: Remote Command Execution Vulnerability on Repository Download Feature Confidential Issue Titles Revealed to Restricted Users on Unsubscribe Disclosure of Milestone Metadata through the Search API Private Project Discovery via Comment Links Metadata of Confidential Issues Disclosed to Restricted Users Mandatory External Authentication Provider Sign-In Restrictions Bypass Internal Projects Allowed to Be Created on in Private Groups Server-Side Request Forgery Through DNS Rebinding Stored Cross-Site Scripting on Wiki Pages Stored Cross-Site Scripting on Notes Repository Password Disclosed on Import Error Page Protected Branches Restriction Rules Bypass Stored Cross-Site Scripting Vulnerability on Child Epics

Solution

freebsd-upgrade-package-gitlab-ce
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.