CVE-2019-18457: High severity gitlab vulnerability
Published Nov 26, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.
Affected Software
2 affected components
GitLab GitLab>=11.8.0<=12.4.0
GitLab GitLab>=11.8.0<=12.4.0
Event History
Nov 26, 2019
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18457?
CVE-2019-18457 has a medium severity rating due to the risk of unauthorized access resulting from insecure permissions.
2
How do I fix CVE-2019-18457?
To fix CVE-2019-18457, update your GitLab installation to version 12.4.1 or later.
3
What systems are affected by CVE-2019-18457?
CVE-2019-18457 affects GitLab Community Edition and Enterprise Edition versions from 11.8.0 to 12.4.0.
4
What type of vulnerability is CVE-2019-18457?
CVE-2019-18457 is categorized as an issue related to insecure permissions in GitLab.
5
Who can exploit CVE-2019-18457?
An attacker with limited access could exploit CVE-2019-18457 to gain enhanced permissions and access sensitive data.