CVE-2019-7549

MEDIUM

GitLab <11.5.10-11.7.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has Incorrect Access Control. The GitLab pipelines feature is vulnerable to authorization issues that allow unauthorized users to view job information.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
gitlab/gitlab 10.0.0 - 11.5.10 (2 CPE variants)
Published May 29, 2019
Tracked Since Feb 18, 2026