CVE-2019-5463: Infoleak
Published Sep 9, 2019
·Updated
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
Affected Software
6 affected components
GitLab GitLab>=11.11.0<11.11.7
GitLab GitLab>=11.11.0<11.11.7
GitLab GitLab>=12.0.0<12.0.4
GitLab GitLab>=12.0.0<12.0.4
GitLab GitLab>=12.1.0<12.1.2
GitLab GitLab>=12.1.0<12.1.2
Event History
Sep 9, 2019
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5463?
The severity of CVE-2019-5463 is classified as a medium risk due to its potential for unauthorized disclosure of build status.
2
How do I fix CVE-2019-5463?
To fix CVE-2019-5463, you should upgrade GitLab to version 12.1.2, 12.0.4, or 11.11.6 or later.
3
Which versions of GitLab are affected by CVE-2019-5463?
CVE-2019-5463 affects GitLab versions 11.11.0 to 11.11.6, 12.0.0 to 12.0.4, and 12.1.0 to 12.1.2.
4
What type of vulnerability is CVE-2019-5463?
CVE-2019-5463 is an authorization issue that can lead to unauthorized disclosure of information.
5
Is CVE-2019-5463 applicable to both GitLab CE and EE?
Yes, CVE-2019-5463 affects both GitLab Community Edition (CE) and Enterprise Edition (EE).