CVE-2019-10109: Infoleak
An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10109?
CVE-2019-10109 is classified as an Information Exposure vulnerability.
How do I fix CVE-2019-10109?
To mitigate CVE-2019-10109, upgrade GitLab to version 11.7.8 or later, or 11.8.4 or later, or 11.9.2 or later.
What impact does CVE-2019-10109 have on GitLab users?
CVE-2019-10109 allows unauthorized access to unremoved EXIF geolocation data in uploaded images.
Which versions of GitLab are affected by CVE-2019-10109?
CVE-2019-10109 affects GitLab Community and Enterprise Editions prior to versions 11.7.8, 11.8.4, and 11.9.2.
Is there a workaround for CVE-2019-10109?
There is no official workaround for CVE-2019-10109; the best course of action is to upgrade to the latest version.