HIGH
CVE-2019-6797
CVSS
7.5
Description
An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.
Summary dbcve.org
GitLab Enterprise Edition leaked GitHub tokens used for CI/CD with External Repos to project maintainers through the UI, allowing unauthorized access to linked GitHub repositories.
Mitigation
Upgrade GitLab to version 11.5.8, 11.6.6, or 11.7.1 or later to patch the information disclosure vulnerability.
EPSS Score
1.53%
Probability of exploitation in next 30 days
73.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.