HIGH

CVE-2019-19314

Gitlab GitLab 2020-01-05 CVSS v3.1
CVSS
7.5

Description

GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

Summary dbcve.org

GitLab Enterprise Edition versions 8.4 through 12.5, 12.4.3, and 12.3.6 stored several authentication tokens in plaintext in the database rather than using proper encryption or hashing, allowing attackers with database access to retrieve these sensitive tokens.

Mitigation

Upgrade GitLab EE to a patched version beyond 12.5, 12.4.3, and 12.3.6. Additionally, rotate any tokens that may have been exposed since the vulnerability allowed plaintext storage.

Weakness (CWE)

CWE-312

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE