ZeroHour

CVE-2019-6995

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p55
Published
()
Modified
Description

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

Vendors
gitlab
Products
gitlab
Weakness
CWE-281
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.