CVE-2019-18450: Medium severity gitlab vulnerability
Published Nov 26, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
Affected Software
2 affected components
GitLab GitLab<=12.4.0
GitLab GitLab<=12.4.0
Event History
Nov 26, 2019
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18450?
CVE-2019-18450 has a medium severity rating due to the potential for unauthorized access resulting from insecure permissions.
2
How do I fix CVE-2019-18450?
To fix CVE-2019-18450, update GitLab Community or Enterprise Edition to version 12.4.1 or later.
3
What is the impact of CVE-2019-18450?
The impact of CVE-2019-18450 includes possible unauthorized access to project labels, which may lead to further data exposure.
4
Is CVE-2019-18450 present in GitLab versions after 12.4?
No, CVE-2019-18450 is not present in GitLab versions after 12.4.0 once patched.
5
What should I do if I cannot update to a fixed version for CVE-2019-18450?
If you cannot update, consider implementing strict access controls and monitoring to mitigate the risks associated with CVE-2019-18450.