An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.
References
Link | Resource |
---|---|
https://about.gitlab.com/releases/2019/07/03/security-release-gitlab-12-dot-0-dot-3-released/ | Vendor Advisory |
https://about.gitlab.com/blog/categories/releases/ | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-10 11:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-13009
Mitre link : CVE-2019-13009
JSON object : View
CWE
Products Affected
gitlab
- gitlab