CVE Vulnerabilities

CVE-2019-13005

Published: Mar 10, 2020 | Modified: Aug 24, 2020
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.10.0 12.0.2
Gitlab Gitlab 11.10.0 12.0.2

References