CVE-2019-18453: Medium severity gitlab vulnerability
Published Nov 26, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.
Affected Software
2 affected components
GitLab GitLab>=11.6.0<=12.4.0
GitLab GitLab>=11.6.0<=12.4.0
Event History
Nov 26, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18453?
CVE-2019-18453 has been classified with a high severity due to insecure permissions related to the add comments via email feature.
2
How do I fix CVE-2019-18453?
To fix CVE-2019-18453, upgrade GitLab Community or Enterprise Edition to version 12.4.1 or later.
3
Which versions of GitLab are affected by CVE-2019-18453?
CVE-2019-18453 affects GitLab Community and Enterprise Editions from 11.6.0 up to 12.4.0.
4
What feature is impacted by CVE-2019-18453?
The add comments via email feature is impacted by CVE-2019-18453 due to insecure permissions.
5
Is CVE-2019-18453 present in GitLab 12.5 or later?
No, CVE-2019-18453 is not present in GitLab version 12.5 or later, as the vulnerability has been addressed.