CRITICAL

CVE-2019-5883

Gitlab GitLab 2019-05-17 CVSS v3.0
CVSS
9.1

Description

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

Summary dbcve.org

GitLab contains an incorrect access control vulnerability in its issue comments feature that allows authenticated users to comment on issues they should not have permission to access. This is a broken access control vulnerability where authorization checks are not properly enforced when creating comments on protected issues.

Mitigation

Upgrade GitLab to version 11.3.11, 11.4.8, 11.5.1 or later to resolve the authorization bypass in the issue comments feature.

EPSS Score

1.5%
Probability of exploitation in next 30 days
73.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE