CVE-2019-10116: Medium severity gitlab vulnerability
Published May 16, 2019
·Updated
An Insecure Permissions issue (issue 3 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Guests of a project were allowed to see Related Branches created for an issue.
Affected Software
6 affected components
GitLab GitLab<11.7.8
GitLab GitLab<11.7.8
GitLab GitLab>=11.8.0<11.8.4
GitLab GitLab>=11.8.0<11.8.4
GitLab GitLab>=11.9.0<11.9.2
GitLab GitLab>=11.9.0<11.9.2
Event History
May 16, 2019
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10116?
CVE-2019-10116 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-10116?
To fix CVE-2019-10116, upgrade GitLab to version 11.7.8, 11.8.4, or 11.9.2 or later.
3
Who is affected by CVE-2019-10116?
CVE-2019-10116 affects GitLab Community and Enterprise Editions prior to versions 11.7.8, 11.8.4, and 11.9.2.
4
What type of vulnerability is CVE-2019-10116?
CVE-2019-10116 is an Insecure Permissions vulnerability that allows guests to see related branches.
5
What versions of GitLab are impacted by CVE-2019-10116?
Versions of GitLab before 11.7.8, from 11.8.0 to 11.8.4, and from 11.9.0 to 11.9.2 are impacted by CVE-2019-10116.