CVE-2019-6996
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.
Se detectó un problema en GitLab Enterprise Edition versiones 10.x (a partir de la 10.6) y versiones 11.x anteriores a 11.5.8, versiones 11.6.x anteriores a 11.6.6 y versiones 11.7.x anteriores a 11.7.1. Presenta un Control de Acceso Incorrecto. La sección de aprobadores de peticiones de fusión presenta un problema de control de acceso que permite a los mantenedores del proyecto visualizar el numero de miembros de grupos privados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-28 CVE Reserved
- 2019-09-09 CVE Published
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gitlab.com/gitlab-org/gitlab-ee/issues/8187 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released | 2020-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 10.6.0 <= 10.8.7 Search vendor "Gitlab" for product "Gitlab" and version " >= 10.6.0 <= 10.8.7" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 10.6.0 <= 10.8.7 Search vendor "Gitlab" for product "Gitlab" and version " >= 10.6.0 <= 10.8.7" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.0.0 < 11.5.8 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.0.0 < 11.5.8" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.0.0 < 11.5.8 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.0.0 < 11.5.8" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.6.0 < 11.6.6 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.6.0 < 11.6.6" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.6.0 < 11.6.6 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.6.0 < 11.6.6" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.7.0 < 11.7.1 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.7.0 < 11.7.1" | community |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.7.0 < 11.7.1 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.7.0 < 11.7.1" | enterprise |
Affected
|