SB2019121833 - Multiple vulnerabilities in GitLab, Gitlab Community Edition
Published: December 18, 2019 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2019-15591)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
2) Information disclosure (CVE-ID: CVE-2019-5487)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
Remediation
Install update from vendor's website.