Insecure Direct Object Reference in GitLab Community and Enterprise Editions
CVE-2019-15582
5.3MEDIUM
Summary
An Insecure Direct Object Reference (IDOR) vulnerability was identified in specific versions of GitLab Community Edition and Enterprise Edition. This weakness enables a maintainer to add any private group to a protected environment, potentially leading to unauthorized access and exposure of sensitive information. It is crucial for users of affected versions to apply the appropriate security updates to mitigate this risk and ensure the integrity of their environments.
Affected Version(s)
GitLab EE before 12.3.2
GitLab EE before 12.2.6
GitLab EE before 12.1.12
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved