PT-2019-14351 · Gitlab · Gitlab Ce/Ee+1

Xanbanx

·

Published

2019-09-17

·

Updated

2021-07-21

·

CVE-2019-15729

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab Community and Enterprise Edition versions 8.18 through 12.2.1
Description An issue was discovered that unintentionally disclosed information about the last pipeline that ran for a merge request due to an internal endpoint.
Recommendations For versions 8.18 through 12.2.1, update to a version that contains a fix for this issue to prevent unintended disclosure of pipeline information.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15729

Affected Products

Gitlab
Gitlab Ce/Ee