MEDIUM

CVE-2019-10110

Gitlab GitLab 2019-05-15 CVSS v3.0
CVSS
6.5

Description

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.

Weakness (CWE)

CWE-732 Incorrect Permission Assignment

EPSS Score

1.17%
Probability of exploitation in next 30 days
65.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE