CVE-2019-6786: Medium severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6786?
CVE-2019-6786 has been classified as a high severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2019-6786?
To fix CVE-2019-6786, update GitLab to version 11.5.8, 11.6.6, or 11.7.1 or later.
What types of GitLab editions are affected by CVE-2019-6786?
Both GitLab Community and Enterprise Editions are affected by CVE-2019-6786 for specific versions prior to the patches.
What is the nature of the vulnerability in CVE-2019-6786?
CVE-2019-6786 involves incorrect access control that allows unauthorized users to access LFS objects.
Can unauthorized users exploit CVE-2019-6786 easily?
Yes, unauthorized users can exploit CVE-2019-6786 if they know the file size and OID of the LFS object.