CVE-2019-7176
Last modified
CVE-2019-7176 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 8.9.0, <= 8.17.8 |
| Gitlab | Gitlab | >= 9.0.0, <= 9.5.10 |
| Gitlab | Gitlab | >= 10.0.0, <= 10.8.6 |
| Gitlab | Gitlab | >= 11.0.0, < 11.5.9 |
| Gitlab | Gitlab | >= 11.6.0, < 11.6.7 |
| Gitlab | Gitlab | >= 11.7.0, < 11.7.2 |
References
- https://gitlab.com/gitlab-org/gitlab-ce/issues/51332Exploit, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/51332Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7176?
How severe is CVE-2019-7176?
How do I fix CVE-2019-7176?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-7170A stored-self XSS exists in Croogo through v3.0.5, allowing …
- CVE-2019-7171A stored-self XSS exists in Croogo through v3.0.5, allowing …
- CVE-2019-7172A stored-self XSS exists in ATutor through v2.2.4, allowing …
- CVE-2019-7173A stored-self XSS exists in Croogo through v3.0.5, allowing …
- CVE-2019-7174Roxy Fileman 1.4.5 allows attackers to execute renamefile.ph…
- CVE-2019-7175In ImageMagick before 7.0.8-25, some memory leaks exist in D…7.5
- CVE-2019-7177Pexip Infinity before 20.1 allows Code Injection onto nodes …7.2
- CVE-2019-7178Pexip Infinity before 20.1 allows privilege escalation by re…7.2
- CVE-2019-7181Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0…
- CVE-2019-7183This improper link resolution vulnerability allows remote at…9.8
- CVE-2019-7184This cross-site scripting (XSS) vulnerability in Video Stati…4.8
- CVE-2019-7185This cross-site scripting (XSS) vulnerability in Music Stati…4.8
Are you affected by CVE-2019-7176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
