MEDIUM

CVE-2019-19254

Gitlab GitLab 2020-01-03 CVSS v3.1
CVSS
5.3

Description

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

Summary dbcve.org

GitLab CE/EE versions 9.6 through 12.5 contain an Incorrect Access Control vulnerability, allowing unauthorized access to resources or functionality due to improper authorization checks.

Mitigation

Upgrade GitLab to a version beyond 12.5 (12.5.1 or later for 12.x, or latest stable release) to resolve the access control issue.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE