CVE-2019-7549
Summary
| CVE | CVE-2019-7549 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-29 16:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access to pipelines and jobs via API although feature disabled (#54358) · Issues · GitLab.org / GitLab FOSS · GitLab | CONFIRM | gitlab.com | |
| GitLab Security Release: 11.7.3, 11.6.8, 11.5.10 | GitLab | MISC | about.gitlab.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.