GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8936 GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:16:46.989Z

Reserved: 2019-11-26T00:00:00

Link: CVE-2019-19312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-05T22:15:10.707

Modified: 2024-11-21T04:34:33.077

Link: CVE-2019-19312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.