PT-2019-15417 · Gitlab+1 · Gitlab Ce/Ee+2

Publicado

2019-11-26

·

Atualizado

2019-11-27

·

CVE-2019-18460

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab Community and Enterprise Edition versions 8.15 through 12.4
Description The issue is related to Incorrect Access Control in the Comments Search feature, which is provided by the Elasticsearch integration.
Recommendations For GitLab Community and Enterprise Edition versions 8.15 through 12.4, update to a version that includes the fix for the Incorrect Access Control issue in the Comments Search feature.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18460

Produtos afetados

Elasticsearch
Gitlab
Gitlab Ce/Ee