CVE-2019-10110: Medium severity gitlab vulnerability
An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which they hold credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10110?
CVE-2019-10110 has a medium severity due to its potential to compromise project namespaces in GitLab.
How do I fix CVE-2019-10110?
To fix CVE-2019-10110, update GitLab Community or Enterprise Edition to version 11.7.8 or later, or to 11.8.4 or later.
Which versions of GitLab are affected by CVE-2019-10110?
CVE-2019-10110 affects GitLab versions before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2.
What type of vulnerability is CVE-2019-10110?
CVE-2019-10110 is classified as an insecure permissions issue.
What impact does CVE-2019-10110 have on GitLab users?
CVE-2019-10110 allows unauthorized users to create projects under any namespace, posing a security risk.