CVE-2019-19314: High severity gitlab vulnerability
Published Jan 5, 2020
·Updated
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
Affected Software
3 affected components
GitLab GitLab>=8.4.0<12.3.8
GitLab GitLab>=12.4.0<12.4.5
GitLab GitLab>=12.5.0<12.5.2
Event History
Jan 5, 2020
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19314?
CVE-2019-19314 has a moderate severity rating due to the storage of tokens in plaintext, which can lead to unauthorized access.
2
How do I fix CVE-2019-19314?
To fix CVE-2019-19314, update GitLab EE to version 12.5.1 or later.
3
What versions of GitLab are affected by CVE-2019-19314?
CVE-2019-19314 affects GitLab EE versions from 8.4 to 12.5, including specific versions 12.4.3 and 12.3.6.
4
Is there a risk of data exposure with CVE-2019-19314?
Yes, CVE-2019-19314 poses a risk of data exposure as it allows tokens stored in plaintext to be compromised.
5
Who should be concerned about CVE-2019-19314?
Organizations using affected versions of GitLab EE should be concerned about CVE-2019-19314 due to the potential security risks.