Gitlab · Gitlab Ce/Ee · CVE-2019-13009
Name of the Vulnerable Software and Affected Versions:
GitLab Community and Enterprise Edition versions 9.2 through 12.0.2
Description:
The issue is related to improper permission settings, allowing unauthorized access to uploaded files associated with unsaved personal snippets. This is due to incorrect access control, which can lead to unauthorized users accessing sensitive information.
Recommendations:
For GitLab Community and Enterprise Edition versions 9.2 through 12.0.2, update to a version that includes the fix for the improper permission settings issue to prevent unauthorized access to uploaded files.