First published: Mon Sep 09 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=6.5.0<11.5.8 | |
GitLab | >=6.5.0<11.5.8 | |
GitLab | >=11.6.0<11.6.6 | |
GitLab | >=11.6.0<11.6.6 | |
GitLab | >=11.7.0<11.7.1 | |
GitLab | >=11.7.0<11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6789 has a medium severity rating due to information disclosure risks.
To fix CVE-2019-6789, update to GitLab Community or Enterprise Edition versions 11.5.8, 11.6.6, or 11.7.1 or later.
Users of GitLab Community and Enterprise Editions prior to versions 11.5.8, 11.6.6, and 11.7.1 are affected by CVE-2019-6789.
CVE-2019-6789 is classified as an Information Disclosure vulnerability.
Failing to address CVE-2019-6789 may result in unauthorized email notifications to users without project permissions.