An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
References
Link | Resource |
---|---|
https://about.gitlab.com/blog/categories/releases/ | Release Notes Vendor Advisory |
https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/ | Vendor Advisory |
https://about.gitlab.com/blog/categories/releases/ | Release Notes Vendor Advisory |
https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-03-10 18:15
Updated : 2024-11-21 04:24
NVD link : CVE-2019-13009
Mitre link : CVE-2019-13009
CVE.ORG link : CVE-2019-13009
JSON object : View
Products Affected
gitlab
- gitlab