CVE-2019-6789: Medium severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6789?
CVE-2019-6789 has a medium severity rating due to information disclosure risks.
How do I fix CVE-2019-6789?
To fix CVE-2019-6789, update to GitLab Community or Enterprise Edition versions 11.5.8, 11.6.6, or 11.7.1 or later.
Who is affected by CVE-2019-6789?
Users of GitLab Community and Enterprise Editions prior to versions 11.5.8, 11.6.6, and 11.7.1 are affected by CVE-2019-6789.
What kind of issue is CVE-2019-6789?
CVE-2019-6789 is classified as an Information Disclosure vulnerability.
What happens if I don't address CVE-2019-6789?
Failing to address CVE-2019-6789 may result in unauthorized email notifications to users without project permissions.