CVE Vulnerabilities

CVE-2019-13002

Published: Mar 10, 2020 | Modified: Jul 21, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.10.0 (including) 12.0.2 (including)

References