First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=9.0.0<=12.0.2 | |
GitLab | >=9.0.0<=12.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13006 has a medium severity rating due to its incorrect access control allowing unauthorized users to view related merge request counts.
To remediate CVE-2019-13006, you should upgrade to GitLab Community or Enterprise Edition version 12.0.3 or later.
CVE-2019-13006 affects users of GitLab Community and Enterprise Edition versions from 9.0.0 to 12.0.2.
CVE-2019-13006 is related to incorrect access control, allowing users with insufficient permissions to access information about merge requests.
Users with access to issues but not the repository are impacted by CVE-2019-13006 as they can view the number of related merge requests.