CVE-2019-15589: High severity gitlab vulnerability
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15589?
CVE-2019-15589 is classified as a moderate severity vulnerability due to improper access control allowing blocked users to access repositories.
How do I fix CVE-2019-15589?
To mitigate CVE-2019-15589, upgrade GitLab to a version higher than 12.3.2, 12.2.6, or 12.1.12.
What versions of GitLab are affected by CVE-2019-15589?
CVE-2019-15589 affects GitLab versions 12.3.2 and earlier, 12.2.6 and earlier, and 12.1.12 and earlier.
What impact does CVE-2019-15589 have on users?
CVE-2019-15589 allows blocked users to clone and pull from GitLab repositories if they possess a CI/CD token.
Is CVE-2019-15589 a remote attack vulnerability?
CVE-2019-15589 can be exploited remotely, as it allows unauthorized access to Git repositories over the internet.