{"id":"CVE-2019-16170","details":"An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.","modified":"2026-03-14T11:51:56.839428Z","published":"2019-09-16T12:15:10.987Z","references":[{"type":"ADVISORY","url":"https://about.gitlab.com/2019/09/10/critical-security-release-gitlab-12-dot-2-dot-5-released/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"4c09765c6424a96be7c7ae7707db3bda4e9c4ab4"},{"fixed":"63f576df77ba4a80c7d2f7c777248084fb3fb373"},{"introduced":"4c09765c6424a96be7c7ae7707db3bda4e9c4ab4"},{"fixed":"63f576df77ba4a80c7d2f7c777248084fb3fb373"},{"introduced":"1f2e6f3f6d84b8eab5526acdd69c38f5b78c3b0e"},{"fixed":"12280cb2177bc3257233163e832713c39028e1b1"},{"introduced":"1f2e6f3f6d84b8eab5526acdd69c38f5b78c3b0e"},{"fixed":"12280cb2177bc3257233163e832713c39028e1b1"},{"introduced":"30032e00da906361c553a1eef4ffcd13378b43ee"},{"fixed":"e817f2e286499307fea462ae3e7b1a6c1d72f0f5"},{"introduced":"30032e00da906361c553a1eef4ffcd13378b43ee"},{"fixed":"e817f2e286499307fea462ae3e7b1a6c1d72f0f5"}],"database_specific":{"versions":[{"introduced":"11.6.0"},{"fixed":"12.0.9"},{"introduced":"11.6.0"},{"fixed":"12.0.9"},{"introduced":"12.1.0"},{"fixed":"12.1.9"},{"introduced":"12.1.0"},{"fixed":"12.1.9"},{"introduced":"12.2.0"},{"fixed":"12.2.5"},{"introduced":"12.2.0"},{"fixed":"12.2.5"}]}}],"versions":["v12.1.0-ee","v12.1.1-ee","v12.1.2-ee","v12.1.3-ee","v12.1.4-ee","v12.1.6-ee","v12.1.8-ee","v12.2.0-ee","v12.2.1-ee","v12.2.3-ee","v12.2.4-ee"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16170.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}