CRITICAL
CVE-2019-5883
CVSS
9.1
Description
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.
Summary dbcve.org
GitLab contains an incorrect access control vulnerability in its issue comments feature that allows authenticated users to comment on issues they should not have permission to access. This is a broken access control vulnerability where authorization checks are not properly enforced when creating comments on protected issues.
Mitigation
Upgrade GitLab to version 11.3.11, 11.4.8, 11.5.1 or later to resolve the authorization bypass in the issue comments feature.
EPSS Score
1.5%
Probability of exploitation in next 30 days
73.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.