CVE Vulnerabilities

CVE-2019-19312

Published: Jan 05, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab8.14.0 (including)12.3.8 (excluding)
GitlabGitlab12.4.0 (including)12.4.5 (excluding)
GitlabGitlab12.5.0 (including)12.5.2 (excluding)

References