CVE-2019-6960
Summary
| CVE | CVE-2019-6960 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-09 20:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
| Application | Gitlab | Gitlab | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 11.7.3, 11.6.8, 11.5.10 | GitLab | CONFIRM | about.gitlab.com | Release Notes, Vendor Advisory |
| Access to internal wiki when using external wiki service (even when wiki is disabled) (#54357) · Issues · GitLab.org / GitLab FOSS · GitLab | CONFIRM | gitlab.com | Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.