First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.10.0<=12.0.2 | |
GitLab | >=11.10.0<=12.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13005 has been classified as a high severity vulnerability due to its potential to disclose sensitive metadata.
To fix CVE-2019-13005, upgrade to GitLab versions 12.0.3 or later.
CVE-2019-13005 is classified as an Incorrect Access Control vulnerability.
CVE-2019-13005 affects GitLab Community Edition and Enterprise Edition versions 11.10.0 through 12.0.2.
CVE-2019-13005 can disclose restricted user, group, and repository metadata to unauthorized users.