Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19312

Опубликовано: 05 янв. 2020
Источник: debian
EPSS Низкий

Описание

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabnot-affectedpackage

Примечания

  • https://about.gitlab.com/blog/2019/11/27/security-release-gitlab-12-5-1-released/

EPSS

Процентиль: 40%
0.00181
Низкий

Связанные уязвимости

CVSS3: 5.8
ubuntu
больше 5 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

CVSS3: 5.8
nvd
больше 5 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

github
около 3 лет назад

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

EPSS

Процентиль: 40%
0.00181
Низкий