CVE-2019-10115
Summary
| CVE | CVE-2019-10115 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 15:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code information. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Guest users of private projects have access to releases (#56402) · Issues · GitLab.org / GitLab Community Edition · GitLab | MISC | gitlab.com | Exploit, Vendor Advisory |
| Releases | GitLab | MISC | about.gitlab.com | Release Notes, Vendor Advisory |
| GitLab Security Release: 11.9.4, 11.8.6, and 11.7.10 | GitLab | MISC | about.gitlab.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.