CVE-2019-6960: Critical severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6960?
CVE-2019-6960 has a medium severity rating due to incorrect access control allowing unauthorized access to the internal wiki.
How do I fix CVE-2019-6960?
To fix CVE-2019-6960, upgrade GitLab to the patched versions 11.5.8, 11.6.6, or 11.7.1 or later.
What versions of GitLab are affected by CVE-2019-6960?
CVE-2019-6960 affects GitLab Community and Enterprise Editions 9.x, 10.x, and 11.x before specific patched versions.
What are the potential risks of exploiting CVE-2019-6960?
Exploiting CVE-2019-6960 could allow an attacker to gain unauthorized access to sensitive internal wiki content.
Is disabling the external wiki service a temporary mitigation for CVE-2019-6960?
Yes, disabling the external wiki service can act as a temporary mitigation until the software is updated.