First published: Mon Sep 16 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.2.0<12.2.3 | |
GitLab | >=12.2.0<12.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15732 is classified as a high-severity vulnerability impacting GitLab versions 12.2 to 12.2.1.
To fix CVE-2019-15732, upgrade to GitLab Community or Enterprise Edition version 12.2.3 or later.
CVE-2019-15732 is an API vulnerability that allows bypassing project visibility restrictions.
The affected versions of GitLab for CVE-2019-15732 are from 12.2.0 to 12.2.1.
Users of GitLab Community and Enterprise Editions in the affected versions are at risk from CVE-2019-15732.