Allele Security Alert
ASA-2019-00221
Identifier(s)
ASA-2019-00221, CVE-2019-10108
Title
Insecure Direct Object Reference (IDOR) labels of private projects/groups
Vendor(s)
GitLab
Product(s)
GitLab Community Edition (CE)
GitLab Enterprise Edition (EE)
Affected version(s)
GitLab CE/EE 8.11.4 and later
Fixed version(s)
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.9.4
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.8.6
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.7.10
Proof of concept
Unknown
Description
An authorization issue was discovered which allowed non-members of a private project/group to add and read labels.
Technical details
Unknown
Credits
vijay_kumar1110
Reference(s)
GitLab Security Release: 11.9.4, 11.8.6, and 11.7.10
https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/
CVE-2019-10108
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10108
CVE-2019-10108
https://nvd.nist.gov/vuln/detail/CVE-2019-10108
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: April 24, 2019