CVE-2019-15727

medium

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

References

https://gitlab.com/gitlab-org/gitlab-ee/issues/11426

https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/

Details

Source: Mitre, NVD

Published: 2019-09-16

Updated: 2019-09-18

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium