CVE-2019-9218: Critical severity gitlab vulnerability
Published May 29, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).
Affected Software
6 affected components
GitLab GitLab<11.6.10
GitLab GitLab<11.6.10
GitLab GitLab>=11.7.0<11.7.6
GitLab GitLab>=11.7.0<11.7.6
GitLab GitLab>=11.8.0<11.8.1
GitLab GitLab>=11.8.0<11.8.1
Event History
May 29, 2019
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-9218?
The severity of CVE-2019-9218 is considered medium due to its incorrect access control issue.
2
How do I fix CVE-2019-9218?
To fix CVE-2019-9218, upgrade GitLab Community or Enterprise Edition to version 11.6.10 or later, or to version 11.7.6 or later.
3
What versions are affected by CVE-2019-9218?
CVE-2019-9218 affects GitLab Community and Enterprise Editions before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
4
What types of products are impacted by CVE-2019-9218?
CVE-2019-9218 impacts both GitLab Community and Enterprise Editions.
5
Is there a workaround for CVE-2019-9218?
There is no documented workaround for CVE-2019-9218; updating to the patched versions is required.