An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab-ce/issues/55537 | Exploit Issue Tracking Third Party Advisory |
https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/ | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-09-09 13:15
Updated : 2019-09-10 11:44
NVD link : CVE-2019-6995
Mitre link : CVE-2019-6995
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
gitlab
- gitlab