MEDIUM
CVE-2019-11549
CVSS
6.5
Description
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
Weakness (CWE)
CWE-532
Sensitive Information in Logs
EPSS Score
1.32%
Probability of exploitation in next 30 days
69.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.