MEDIUM
CVE-2019-19256
CVSS
5.3
Description
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
Summary dbcve.org
GitLab Enterprise Edition versions 12.2 through 12.5 contains an Incorrect Access Control vulnerability that allows unauthorized access to certain resources or functionality due to improper authorization checks.
Mitigation
Upgrade GitLab EE to version 12.5.1 or later which contains the patch for this access control issue. If immediate upgrading is not possible, review user role permissions and restrict access to sensitive features as a temporary measure.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.93%
Probability of exploitation in next 30 days
59th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.