HIGH
CVE-2019-19314
CVSS
7.5
Description
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
Summary dbcve.org
GitLab Enterprise Edition versions 8.4 through 12.5, 12.4.3, and 12.3.6 stored several authentication tokens in plaintext in the database rather than using proper encryption or hashing, allowing attackers with database access to retrieve these sensitive tokens.
Mitigation
Upgrade GitLab EE to a patched version beyond 12.5, 12.4.3, and 12.3.6. Additionally, rotate any tokens that may have been exposed since the vulnerability allowed plaintext storage.
Weakness (CWE)
CWE-312
EPSS Score
0.81%
Probability of exploitation in next 30 days
55.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.