CVE-2019-9756

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.… (CVE-2019-9756)

criticalEPSS 2.1%

Description

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-9732.

Source: NVDCVELISTV5

Metrics

Severity
critical
no public PoC known
9.8
Source: nvd-v3
81.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
2.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-04-17 16:11 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • gitlab

    gitlab10.8.0 – 10.8.7

  • gitlab

    gitlab11.0.0 – 11.6.10

  • gitlab

    gitlab11.8.0 – 11.8.1

References & sources

IDCVE-2019-9756