Authorization bypass through user-controlled key in Gitlab Community Edition - CVE-2019-5469

 

Authorization bypass through user-controlled key in Gitlab Community Edition - CVE-2019-5469

Published: December 18, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30518
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5469
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to manipulate data.

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.


Affected software

Gitlab Community Edition

How to mitigate CVE-2019-5469

Install update from vendor's website.

Gitlab Community Edition - update to 12.1.2

External References

Related Security Bulletins