Vulnerabilities > CVE-2019-16170 - Unspecified vulnerability in Gitlab

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
NONE
network
low complexity
gitlab
nessus

Summary

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

Vulnerable Configurations

Part Description Count
Application
Gitlab
186

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_B2789B2DD52111E986E9001B217B3468.NASL
descriptionGitlab reports : Project Template Functionality Could Be Used to Access Restricted Project Data Security Enhancements in GitLab Pages
last seen2020-06-01
modified2020-06-02
plugin id129547
published2019-10-03
reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/129547
titleFreeBSD : Gitlab -- Multiple Vulnerabilities (b2789b2d-d521-11e9-86e9-001b217b3468)