CVE-2019-6996: Medium severity gitlab vulnerability
An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6996?
CVE-2019-6996 is rated as a medium severity vulnerability due to its incorrect access control that allows project maintainers to view restricted information.
How do I fix CVE-2019-6996?
To fix CVE-2019-6996, upgrade your GitLab instance to version 11.5.8 or later.
Which versions of GitLab are affected by CVE-2019-6996?
CVE-2019-6996 affects GitLab Enterprise Edition versions 10.x (starting from 10.6) and 11.x before 11.5.8, along with specific ranges up to 11.7.1.
What type of vulnerability is CVE-2019-6996?
CVE-2019-6996 is classified as an Incorrect Access Control vulnerability.
What functionality is compromised by CVE-2019-6996?
CVE-2019-6996 compromises the merge request approvers section by allowing unauthorized visibility of project membership.