First published: Mon Sep 16 2019(Updated: )
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=7.4.0<12.0.8 | |
GitLab | >=12.1.0<12.1.8 | |
GitLab | >=12.2.0<12.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15741 is classified as a medium severity vulnerability that can lead to privilege escalation.
To fix CVE-2019-15741, you should upgrade your GitLab Omnibus installation to version 12.2.3 or later.
CVE-2019-15741 affects GitLab Omnibus versions from 7.4.0 to 12.2.1.
Exploitation of CVE-2019-15741 could allow an unauthorized user to gain elevated privileges on the affected system.
Currently, there is no known workaround for CVE-2019-15741; upgrading is the recommended action.