MEDIUM

CVE-2019-12433

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
5.3

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.

Summary dbcve.org

GitLab fails to properly validate visibility settings when creating projects in private groups. The input validation flaw allows users to create internal projects within private groups despite restricted visibility settings being enabled, leading to unintended permission exposures where project access may be granted to unauthorized users.

Mitigation

Upgrade GitLab to a version beyond 11.11 that contains the patch for this improper input validation issue in visibility settings.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

0.82%
Probability of exploitation in next 30 days
55.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE