CVE-2019-16170

HIGH

GitLab EE <12.0.9-12.2.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

Status published
Products (1)
gitlab/gitlab 11.6.0 - 12.0.9 (2 CPE variants)
Published Sep 16, 2019
Tracked Since Feb 18, 2026