CVE-2019-9756: Critical severity gitlab vulnerability
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9756?
CVE-2019-9756 has a medium severity rating due to its Incorrect Access Control vulnerabilities.
How do I fix CVE-2019-9756?
To fix CVE-2019-9756, update GitLab to version 11.6.10 or later for versions 11.x, and for version 10.x upgrade to 10.8.8 or later.
What versions of GitLab are affected by CVE-2019-9756?
CVE-2019-9756 affects GitLab Community and Enterprise Editions from versions 10.8.0 to 10.8.7, 11.0.0 to 11.6.10, and 11.8.0 to 11.8.1.
What is the impact of CVE-2019-9756?
The impact of CVE-2019-9756 allows unauthorized users to access some GitLab resources due to access control misconfigurations.
Is CVE-2019-9756 related to other CVEs?
Yes, CVE-2019-9756 is a different vulnerability from CVE-2019-9732, both affecting GitLab but with distinct issues.