HIGH

CVE-2019-19629

Gitlab GitLab 2020-01-05 CVSS v3.1
CVSS
7.5

Description

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

Summary dbcve.org

In GitLab EE versions 10.5 through 12.5.3, 12.4.5, and 12.3.8, when a public project is transferred to a private group with the Elasticsearch integration enabled, the Group Search API improperly exposes private code that should remain confidential. This occurs because the Elasticsearch index retains access to the project's code even after the project visibility changes.

Mitigation

Upgrade GitLab to a patched version (12.6.2, 12.5.6, or 12.4.6+) or disable the Elasticsearch integration as a temporary workaround until the upgrade can be completed.

EPSS Score

1.16%
Probability of exploitation in next 30 days
65.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE