← Back

CVE-2019-5469

nvd nist
Published: Dec 18, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

Affected (6)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 11.11.0 to 11.11.6
From 12.0.0 to 12.0.4
From 12.1.0 to 12.1.2
From 11.11.0 to 11.11.6
From 12.0.0 to 12.0.4
From 12.1.0 to 12.1.2

References (4)

Source: support@hackerone.com
ExploitVendor Advisory
Source: support@hackerone.com
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.