CVE-2019-15736: High severity gitlab vulnerability
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.
Affected Software
6 affected components
GitLab GitLab<12.0.8
GitLab GitLab<12.0.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.2.0<12.2.3
GitLab GitLab>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15736?
CVE-2019-15736 is considered a denial of service vulnerability that can disrupt CI pipelines in GitLab.
2
How do I fix CVE-2019-15736?
To remediate CVE-2019-15736, upgrade to GitLab versions 12.2.2 or later.
3
What GitLab versions are affected by CVE-2019-15736?
CVE-2019-15736 affects GitLab Community and Enterprise Editions from version 12.0.0 up to 12.2.1.
4
Can CVE-2019-15736 lead to service interruptions?
Yes, CVE-2019-15736 could potentially be exploited to cause service interruptions through manipulated CI pipelines.
5
Is CVE-2019-15736 related to CI pipelines in GitLab?
Yes, CVE-2019-15736 specifically impacts CI pipelines, enabling a potential denial of service attack.