CVE-2019-11549: Medium severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11549?
CVE-2019-11549 has been classified as a medium severity vulnerability as it allows potential information disclosure.
How do I fix CVE-2019-11549?
To fix CVE-2019-11549, upgrade to GitLab version 11.8.9, 11.9.10, or 11.10.2 or later.
What types of systems are affected by CVE-2019-11549?
CVE-2019-11549 affects GitLab Community and Enterprise Editions version 9.x through 11.x up to specified versions.
What does CVE-2019-11549 exploit?
CVE-2019-11549 exploits an information disclosure issue in Gitaly where HTTP/GIT credentials may be logged on connection errors.
What are the potential risks of CVE-2019-11549?
The potential risks of CVE-2019-11549 include unauthorized access to sensitive credentials that could compromise repository security.