HIGH
CVE-2019-19629
CVSS
7.5
Description
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
Summary dbcve.org
In GitLab EE versions 10.5 through 12.5.3, 12.4.5, and 12.3.8, when a public project is transferred to a private group with the Elasticsearch integration enabled, the Group Search API improperly exposes private code that should remain confidential. This occurs because the Elasticsearch index retains access to the project's code even after the project visibility changes.
Mitigation
Upgrade GitLab to a patched version (12.6.2, 12.5.6, or 12.4.6+) or disable the Elasticsearch integration as a temporary workaround until the upgrade can be completed.
EPSS Score
1.16%
Probability of exploitation in next 30 days
65.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.