CVE-2019-7155

MEDIUM

GitLab <11.5.8-11.7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains their role within a project in a private group after being removed from the group, if their privileges within the project are different from the group.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/42726

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269
Status published
Products (1)
gitlab/gitlab 9.0.0 - 11.5.8 (2 CPE variants)
Published Apr 16, 2019
Tracked Since Feb 18, 2026