An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.
References
Link | Resource |
---|---|
https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/ | Release Notes Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab-ce/issues/55537 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-09-09 20:15
Updated : 2019-09-10 18:44
NVD link : CVE-2019-6995
Mitre link : CVE-2019-6995
CVE.ORG link : CVE-2019-6995
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-281
Improper Preservation of Permissions