Medium severity6.5NVD Advisory· Published Dec 18, 2019· Updated Jun 17, 2026
CVE-2019-5469
CVE-2019-5469
Description
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.11.0,<11.11.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.11.0,<11.11.6
- (no CPE)range: <12.1.2, <12.0.4, <11.11.6
- GitLab/GitLabdescription
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab-ce/issues/60551nvdExploitVendor Advisory
- hackerone.com/reports/534794nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.