CVE Vulnerabilities

CVE-2019-19312

Published: Jan 05, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.14.0 (including) 12.3.8 (excluding)
Gitlab Gitlab 12.4.0 (including) 12.4.5 (excluding)
Gitlab Gitlab 12.5.0 (including) 12.5.2 (excluding)

References