HIGH

CVE-2019-6797

Gitlab GitLab 2019-05-17 CVSS v3.0
CVSS
7.5

Description

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

Summary dbcve.org

GitLab Enterprise Edition leaked GitHub tokens used for CI/CD with External Repos to project maintainers through the UI, allowing unauthorized access to linked GitHub repositories.

Mitigation

Upgrade GitLab to version 11.5.8, 11.6.6, or 11.7.1 or later to patch the information disclosure vulnerability.

EPSS Score

1.53%
Probability of exploitation in next 30 days
73.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE