CVE-2019-15741: Critical severity gitlab vulnerability
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
Affected Software
3 affected components
GitLab Omnibus>=7.4.0<12.0.8
GitLab Omnibus>=12.1.0<12.1.8
GitLab Omnibus>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15741?
CVE-2019-15741 is classified as a medium severity vulnerability that can lead to privilege escalation.
2
How do I fix CVE-2019-15741?
To fix CVE-2019-15741, you should upgrade your GitLab Omnibus installation to version 12.2.3 or later.
3
Which versions of GitLab Omnibus are affected by CVE-2019-15741?
CVE-2019-15741 affects GitLab Omnibus versions from 7.4.0 to 12.2.1.
4
What consequences could result from exploiting CVE-2019-15741?
Exploitation of CVE-2019-15741 could allow an unauthorized user to gain elevated privileges on the affected system.
5
Is there a workaround for CVE-2019-15741?
Currently, there is no known workaround for CVE-2019-15741; upgrading is the recommended action.