CVE-2019-12429: Medium severity gitlab vulnerability
Published Mar 10, 2020
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
Affected Software
2 affected components
GitLab GitLab>=11.9.0<=11.11.0
GitLab GitLab>=11.9.0<=11.11.0
Event History
Mar 10, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12429?
CVE-2019-12429 has a medium severity rating due to improper access control issues.
2
How do I fix CVE-2019-12429?
To fix CVE-2019-12429, upgrade to GitLab Community or Enterprise Edition version 11.11.1 or later.
3
Who is affected by CVE-2019-12429?
CVE-2019-12429 affects GitLab Community and Enterprise Editions from version 11.9 to 11.11.0.
4
What types of information can unprivileged users access in CVE-2019-12429?
Unprivileged users can access labels, status, and merge request counts of confidential issues.
5
What is the nature of the vulnerability in CVE-2019-12429?
CVE-2019-12429 is an issue of improper access control that allows unauthorized information disclosure.