A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.
An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.