CVE-2019-12431: Medium severity gitlab vulnerability
Published Mar 10, 2020
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.
Affected Software
2 affected components
GitLab GitLab>=8.13.0<=11.11.0
GitLab GitLab>=8.13.0<=11.11.0
Event History
Mar 10, 2020
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12431?
CVE-2019-12431 has a medium severity rating due to improper access control allowing restricted users to access private milestone metadata.
2
How do I fix CVE-2019-12431?
To fix CVE-2019-12431, upgrade your GitLab installation to version 11.11.1 or later.
3
What versions of GitLab are affected by CVE-2019-12431?
CVE-2019-12431 affects GitLab Community and Enterprise Editions from versions 8.13.0 to 11.11.0.
4
Can restricted users exploit CVE-2019-12431?
Yes, restricted users can exploit CVE-2019-12431 to access metadata of private milestones via the Search API.
5
Is there a patch for CVE-2019-12431?
Yes, a patch for CVE-2019-12431 is included in the GitLab release version 11.11.1 and later.