First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.10.0<=12.0.2 | |
GitLab | >=11.10.0<=12.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13002 is classified as a medium severity vulnerability due to its incorrect access control allowing unauthorized access to sensitive data.
To fix CVE-2019-13002, you should upgrade GitLab to version 12.0.3 or later.
CVE-2019-13002 affects both GitLab Community Edition and Enterprise Edition versions from 11.10.0 up to 12.0.2.
Due to CVE-2019-13002, unauthorized users could read pipeline information related to the last merge request.
Organizations using affected versions of GitLab are at risk if they have not implemented the recommended security updates.