CVE-2019-10115: Medium severity gitlab vulnerability
An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10115?
CVE-2019-10115 is considered a moderate severity vulnerability due to the potential exposure of private information.
How do I fix CVE-2019-10115?
To mitigate CVE-2019-10115, update GitLab to version 11.7.8, 11.8.4, or 11.9.2 or later.
What does CVE-2019-10115 affect?
CVE-2019-10115 affects the GitLab Community and Enterprise Editions prior to version 11.7.8, 11.8.4, and 11.9.2.
Who can exploit CVE-2019-10115?
CVE-2019-10115 can be exploited by guest users to access restricted release details and code information.
Is CVE-2019-10115 part of a series of issues?
Yes, CVE-2019-10115 is identified as issue 2 of 3 related to insecure permissions in GitLab.