CVE-2019-10108: Medium severity gitlab vulnerability
An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. It allowed non-members of a private project/group to add and read labels.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10108?
CVE-2019-10108 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-10108?
To fix CVE-2019-10108, update your GitLab to a version equal to or greater than 11.7.8, 11.8.4, or 11.9.2.
What types of software are affected by CVE-2019-10108?
CVE-2019-10108 affects GitLab Community and Enterprise Editions prior to versions 11.7.8, 11.8.4, and 11.9.2.
What does CVE-2019-10108 exploit?
CVE-2019-10108 exploits incorrect access control allowing non-members to add and read labels in private projects or groups.
What versions are vulnerable to CVE-2019-10108?
Versions of GitLab prior to 11.7.8, 11.8.0 to 11.8.4, and 11.9.0 to 11.9.2 are vulnerable to CVE-2019-10108.