PT-2020-9363 · Gitlab · Gitlab Ce/Ee+1
Mkozon
·
Published
2020-03-10
·
Updated
2020-08-24
·
CVE-2019-13009
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
GitLab Community and Enterprise Edition versions 9.2 through 12.0.2
Description:
The issue is related to improper permission settings, allowing unauthorized access to uploaded files associated with unsaved personal snippets. This is due to incorrect access control, which can lead to unauthorized users accessing sensitive information.
Recommendations:
For GitLab Community and Enterprise Edition versions 9.2 through 12.0.2, update to a version that includes the fix for the improper permission settings issue to prevent unauthorized access to uploaded files.
Fix
Incorrect Permission
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee