MEDIUM
CVE-2019-19254
CVSS
5.3
Description
GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.
Summary dbcve.org
GitLab CE/EE versions 9.6 through 12.5 contain an Incorrect Access Control vulnerability, allowing unauthorized access to resources or functionality due to improper authorization checks.
Mitigation
Upgrade GitLab to a version beyond 12.5 (12.5.1 or later for 12.x, or latest stable release) to resolve the access control issue.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.