CVE-2019-13005 describes an Incorrect Access Control vulnerability within the GitLab Enterprise and Community Editions, versions 1.10 through 12.0.2. This flaw allowed unauthorized users to access restricted user, group, and repository metadata via the GitLab GraphQL service. Rated Medium with a CVSS score of 4.3, it is a network-based vulnerability with low attack complexity, requiring low privileges to disclose sensitive information. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.10.0, <= 12.0.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.10.0, <= 12.0.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.