First published: Tue Mar 10 2020(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=9.2.0<=12.0.2 | |
GitLab | >=9.2.0<=12.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13009 has been classified as a medium severity vulnerability due to improper permissions allowing unauthorized access.
To fix CVE-2019-13009, users should update to GitLab versions 12.0.3 or later, which address the improper access control issue.
CVE-2019-13009 affects both GitLab Community and Enterprise Edition versions 9.2 to 12.0.2.
CVE-2019-13009 is an access control vulnerability that allows unauthorized users to access uploaded files from unsaved personal snippets.
Exploitation of CVE-2019-13009 can be conducted by unauthorized users who leverage the improper permission settings in GitLab.