CVE-2019-15740: Infoleak
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.
Affected Software
6 affected components
GitLab GitLab>=7.9.0<12.0.8
GitLab GitLab>=7.9.0<12.0.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.2.0<12.2.3
GitLab GitLab>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15740?
CVE-2019-15740 has a medium severity level due to the potential exposure of sensitive geolocation information.
2
How do I fix CVE-2019-15740?
To fix CVE-2019-15740, update GitLab to version 12.2.3 or later for both Community and Enterprise editions.
3
Which versions of GitLab are affected by CVE-2019-15740?
CVE-2019-15740 affects GitLab Community and Enterprise Editions from versions 7.9 through 12.2.1.
4
What kind of data exposure is associated with CVE-2019-15740?
CVE-2019-15740 is associated with the exposure of EXIF geolocation data from certain image uploads.
5
Is there a workaround for CVE-2019-15740?
There is no specific workaround for CVE-2019-15740; upgrading to the fixed version is the recommended action.