Unauthorized Access to Pipeline Information in GitLab Community and Enterprise Edition 11.10 through 12.0.2

Unauthorized Access to Pipeline Information in GitLab Community and Enterprise Edition 11.10 through 12.0.2

CVE-2019-13002 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

Learn more about our User Device Pen Test.