First published: Mon Sep 09 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.9.0<11.5.8 | |
GitLab | >=8.9.0<11.5.8 | |
GitLab | >=11.6.0<11.6.6 | |
GitLab | >=11.6.0<11.6.6 | |
GitLab | >=11.7.0<11.7.1 | |
GitLab | >=11.7.0<11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6792 has a medium severity rating due to the potential exposure of sensitive internal information.
To fix CVE-2019-6792, update GitLab to version 11.5.8, 11.6.6, or 11.7.1 or later.
CVE-2019-6792 is a Path Disclosure vulnerability that reveals internal instance information during error handling.
CVE-2019-6792 affects GitLab Community and Enterprise Editions before versions 11.5.8, 11.6.6, and 11.7.1.
CVE-2019-6792 can lead to an attacker gaining insights into the internal structure of the GitLab instance through error messages.