First published: Wed May 29 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.0.0<11.5.10 | |
GitLab | >=10.0.0<11.5.10 | |
GitLab | >=11.6.0<11.6.8 | |
GitLab | >=11.6.0<11.6.8 | |
GitLab | >=11.7.0<11.7.3 | |
GitLab | >=11.7.0<11.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7549 has a severity rating that indicates a significant risk of unauthorized access to job information in GitLab.
To address CVE-2019-7549, users should upgrade to GitLab versions 11.5.10, 11.6.8, or 11.7.3 or later.
CVE-2019-7549 affects GitLab Community and Enterprise Editions from version 10.0.0 to 11.5.10 and various 11.x versions below 11.7.3.
CVE-2019-7549 is classified as an Incorrect Access Control vulnerability.
CVE-2019-7549 can be exploited by unauthorized users who gain access to view sensitive job information in GitLab pipelines.