MEDIUM
CVE-2019-12433
CVSS
5.3
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settings allow creating internal projects in private groups, leading to multiple permission issues.
Summary dbcve.org
GitLab fails to properly validate visibility settings when creating projects in private groups. The input validation flaw allows users to create internal projects within private groups despite restricted visibility settings being enabled, leading to unintended permission exposures where project access may be granted to unauthorized users.
Mitigation
Upgrade GitLab to a version beyond 11.11 that contains the patch for this improper input validation issue in visibility settings.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
0.82%
Probability of exploitation in next 30 days
55.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.