First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.10.0<=12.0.2 | |
GitLab | >=11.10.0<=12.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13004 has a moderate severity level due to its impact on access control in comments.
To fix CVE-2019-13004, upgrade GitLab to version 12.0.3 or higher.
CVE-2019-13004 affects GitLab Community and Enterprise Edition versions 11.10 through 12.0.2.
The impact of CVE-2019-13004 is that comments with specific encoded characters become inaccessible to users.
CVE-2019-13004 is part of two identified issues related to incorrect access control in GitLab.