HIGH

CVE-2019-11605

Gitlab GitLab 2019-09-09 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

Summary dbcve.org

A small number of GitLab API endpoints improperly disclosed project information when accessed with read_user scoped tokens. The read_user scope is intended to provide limited access to user-specific data, but certain endpoints were returning project-related information that should not have been accessible at that privilege level.

Mitigation

Upgrade GitLab to version 11.8.10, 11.9.11, or 11.10.3 or later to resolve the improper information disclosure via read_user scoped API tokens.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE