VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026

CVE-2019-6786

CVE-2019-6786

Description

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • GitLab/GitLab Community and Enterprise Editiondescription
  • Range: <11.5.8, 11.6.x <11.6.6, 11.7.x <11.7.1
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 1 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.16.0,<11.5.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.16.0,<11.5.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.