CVE-2019-5469: Medium severity gitlab vulnerability
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5469?
CVE-2019-5469 is rated as a high severity vulnerability that allows unauthorized file replacements in GitLab.
How do I fix CVE-2019-5469?
To fix CVE-2019-5469, upgrade your GitLab instance to versions 12.1.3, 12.0.5, or 11.11.7 or later.
What is the impact of CVE-2019-5469?
The impact of CVE-2019-5469 includes potential data integrity issues through unauthorized file replacements.
Which versions of GitLab are affected by CVE-2019-5469?
CVE-2019-5469 affects GitLab versions prior to 12.1.3, 12.0.5, and 11.11.7.
Is there a workaround for CVE-2019-5469?
There are no known workarounds for CVE-2019-5469, so the recommended action is to perform the necessary software upgrade.