MEDIUM

CVE-2019-19312

Gitlab GitLab 2020-01-05 CVSS v3.1
CVSS
5.8

Description

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

Summary dbcve.org

GitLab EE versions 8.14 through 12.5, 12.4.3, and 12.3.6 had an incorrect access control vulnerability where forked repositories retained access to private project information via the API after the parent project was changed to private.

Mitigation

Upgrade GitLab to a patched version that resolves this access control bypass in fork-to-private project scenarios.

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE