First published: Mon Sep 16 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.6.0<12.0.8 | |
GitLab | >=8.6.0<12.0.8 | |
GitLab | >=12.1.0<12.1.8 | |
GitLab | >=12.1.0<12.1.8 | |
GitLab | >=12.2.0<12.2.3 | |
GitLab | >=12.2.0<12.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-15734 is classified as medium due to unauthorized access to certain commit titles and comments under specific conditions.
CVE-2019-15734 affects users of GitLab Community and Enterprise Editions versions 8.6 through 12.2.1.
To fix CVE-2019-15734, update your GitLab installation to version 12.2.3 or later.
The potential impacts of CVE-2019-15734 include unauthorized visibility of commit titles and team member comments.
There are no specific workarounds for CVE-2019-15734; upgrading is the recommended action.