ASA-2019-00221 – GitLab: Insecure Direct Object Reference (IDOR) labels of private projects/groups


Allele Security Alert

ASA-2019-00221

Identifier(s)

ASA-2019-00221, CVE-2019-10108

Title

Insecure Direct Object Reference (IDOR) labels of private projects/groups

Vendor(s)

GitLab

Product(s)

GitLab Community Edition (CE)
GitLab Enterprise Edition (EE)

Affected version(s)

GitLab CE/EE 8.11.4 and later

Fixed version(s)

GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.9.4
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.8.6
GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) 11.7.10

Proof of concept

Unknown

Description

An authorization issue was discovered which allowed non-members of a private project/group to add and read labels.

Technical details

Unknown

Credits

vijay_kumar1110

Reference(s)

GitLab Security Release: 11.9.4, 11.8.6, and 11.7.10
https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/

CVE-2019-10108
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10108

CVE-2019-10108
https://nvd.nist.gov/vuln/detail/CVE-2019-10108

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: April 24, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.