HIGH

CVE-2019-12441

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

Summary dbcve.org

GitLab Community and Enterprise Edition 8.4 through 11.11 contains an Incorrect Access Control vulnerability in the protected branches feature, allowing authenticated users to bypass restriction rules meant to protect branches from unauthorized modifications such as force pushes, deletion, or merges.

Mitigation

Upgrade GitLab to a version beyond 11.11 where the access control logic for protected branches has been corrected.

Weakness (CWE)

CWE-732 Incorrect Permission Assignment

EPSS Score

0.94%
Probability of exploitation in next 30 days
59.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE