ASA-2019-00223 – GitLab: Group Runner Registration Token Exposure


Allele Security Alert

ASA-2019-00223

Identifier(s)

ASA-2019-00223, CVE-2019-11000

Title

Group Runner Registration Token Exposure

Vendor(s)

GitLab

Product(s)

GitLab Enterprise Edition (EE)

Affected version(s)

GitLab EE 10.4 and later

Fixed version(s)

GitLab Enterprise Edition (EE) 11.9.7
GitLab Enterprise Edition (EE) 11.8.7
GitLab Enterprise Edition (EE) 11.7.11

Proof of concept

Unknown

Description

The GitLab groups API was vulnerable to an information disclosure issue that disclosed group runner registration tokens to unauthorized users.

Technical details

Unknown

Credits

storm_spirit

Reference(s)

GitLab Critical Security Release: 11.9.7, 11.8.7, and 11.7.11
https://about.gitlab.com/2019/04/10/critical-security-release-gitlab-11-dot-9-dot-7-released/

CVE-2019-11000
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11000

CVE-2019-11000
https://nvd.nist.gov/vuln/detail/CVE-2019-11000

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: April 24, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.