MEDIUM

CVE-2019-19256

Gitlab GitLab 2020-01-03 CVSS v3.1
CVSS
5.3

Description

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

Summary dbcve.org

GitLab Enterprise Edition versions 12.2 through 12.5 contains an Incorrect Access Control vulnerability that allows unauthorized access to certain resources or functionality due to improper authorization checks.

Mitigation

Upgrade GitLab EE to version 12.5.1 or later which contains the patch for this access control issue. If immediate upgrading is not possible, review user role permissions and restrict access to sensitive features as a temporary measure.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.93%
Probability of exploitation in next 30 days
59th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE