PT-2020-9363 · Gitlab · Gitlab Ce/Ee+1

Mkozon

·

Published

2020-03-10

·

Updated

2020-08-24

·

CVE-2019-13009

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GitLab Community and Enterprise Edition versions 9.2 through 12.0.2
Description: The issue is related to improper permission settings, allowing unauthorized access to uploaded files associated with unsaved personal snippets. This is due to incorrect access control, which can lead to unauthorized users accessing sensitive information.
Recommendations: For GitLab Community and Enterprise Edition versions 9.2 through 12.0.2, update to a version that includes the fix for the improper permission settings issue to prevent unauthorized access to uploaded files.

Fix

Incorrect Permission

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13009

Affected Products

Gitlab
Gitlab Ce/Ee