CVE-2019-12446: High severity gitlab vulnerability
Published Mar 10, 2020
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.
Affected Software
2 affected components
GitLab GitLab>=8.3.0<=11.11.0
GitLab GitLab>=8.3.0<=11.11.0
Event History
Mar 10, 2020
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12446?
CVE-2019-12446 is classified as a medium severity vulnerability due to the information exposure risk it poses.
2
How do I fix CVE-2019-12446?
To fix CVE-2019-12446, update GitLab Community or Enterprise Edition to version 11.11.1 or later.
3
What types of software are affected by CVE-2019-12446?
CVE-2019-12446 affects GitLab Community Edition and Enterprise Edition versions between 8.3.0 and 11.11.0.
4
What is the impact of CVE-2019-12446?
The impact of CVE-2019-12446 is that it allows unauthorized access to sensitive information through error messages.
5
Is there a workaround for CVE-2019-12446?
There is no known workaround for CVE-2019-12446, and upgrading to a patched version is the recommended action.