ASA-2019-00214 – GitLab: Improper authorization control “move issue”


Allele Security Alert

ASA-2019-00214

Identifier(s)

ASA-2019-00214, CVE-2019-10110

Title

Improper authorization control “move issue”

Vendor(s)

GitLab

Product(s)

GitLab Community Edition (CE)
GitLab Enterprise Edition (EE)

Affected version(s)

GitLab CE/EE 11.7 and later

Fixed version(s)

GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.9.4
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.8.6
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.7.10

Proof of concept

Unknown

Description

An authorization issue was discovered in the “move issue” feature which could allow an attackers to create projects under any namespace on any GitLab instance on which they already hold credentials.

Technical details

Unknown

Credits

mishre

Reference(s)

GitLab Security Release: 11.9.4, 11.8.6, and 11.7.10
https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: April 24, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.