Vulnerabilities > CVE-2019-16170 - Unspecified vulnerability in Gitlab

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
gitlab
nessus

Summary

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

Vulnerable Configurations

Part Description Count
Application
Gitlab
186

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_B2789B2DD52111E986E9001B217B3468.NASL
descriptionGitlab reports : Project Template Functionality Could Be Used to Access Restricted Project Data Security Enhancements in GitLab Pages
last seen2020-06-01
modified2020-06-02
plugin id129547
published2019-10-03
reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/129547
titleFreeBSD : Gitlab -- Multiple Vulnerabilities (b2789b2d-d521-11e9-86e9-001b217b3468)