PT-2019-14351 · Gitlab · Gitlab Ce/Ee+1

Xanbanx

·

Publicado

2019-09-17

·

Atualizado

2021-07-21

·

CVE-2019-15729

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab Community and Enterprise Edition versions 8.18 through 12.2.1
Description An issue was discovered that unintentionally disclosed information about the last pipeline that ran for a merge request due to an internal endpoint.
Recommendations For versions 8.18 through 12.2.1, update to a version that contains a fix for this issue to prevent unintended disclosure of pipeline information.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15729

Produtos afetados

Gitlab
Gitlab Ce/Ee