SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12825

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre.

MEDIUM 4.3EPSS 1.10%

Does this matter?

Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.

Description

Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.10% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
gitlab/gitlab
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.