CVE-2019-13001

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-13001
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13001.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-13001
Published
2020-03-10T15:15:15.557Z
Modified
2025-11-19T17:35:30.728808Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13001.json"