First published: Wed Dec 18 2019(Updated: )
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <12.1.12 | |
GitLab | <12.1.12 | |
GitLab | >=12.2.0<12.2.6 | |
GitLab | >=12.2.0<12.2.6 | |
GitLab | >=12.3.0<12.3.2 | |
GitLab | >=12.3.0<12.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GitLab CE/EE versions prior to 12.3.2, 12.2.6, and 12.1.12 are affected by CVE-2019-15575.
CVE-2019-15575 is a command injection vulnerability that allows attackers to inject commands via the API through the blobs scope.
CVE-2019-15575 is considered a critical severity vulnerability due to its potential for remote command execution.
To mitigate CVE-2019-15575, upgrade GitLab to a version that is not affected, specifically to versions 12.3.2 or later, 12.2.6 or later, or 12.1.12 or later.
Yes, both the Community and Enterprise editions of GitLab are affected by CVE-2019-15575.