CVE-2019-10117: Medium severity gitlab vulnerability
An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10117?
CVE-2019-10117 is categorized as a medium-severity vulnerability due to its ability to lead to open redirects after user authentication.
How do I fix CVE-2019-10117?
To fix CVE-2019-10117, upgrade to GitLab versions 11.7.8, 11.8.4, or 11.9.2 or later.
What versions of GitLab are affected by CVE-2019-10117?
CVE-2019-10117 affects GitLab Community and Enterprise Editions prior to versions 11.7.8, 11.8.4, and 11.9.2.
What does CVE-2019-10117 exploit?
CVE-2019-10117 exploits an Open Redirect vulnerability in the Oauth/:GeoAuthController after successful authentication.
Is CVE-2019-10117 exploitable remotely?
Yes, CVE-2019-10117 can be exploited remotely since it allows manipulation of redirect URLs after user authentication.