Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab-ce/issues/52444 | Issue Tracking Vendor Advisory |
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/ | Broken Link Release Notes Vendor Advisory |
http://www.securityfocus.com/bid/109179 | Broken Link Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-07-10 08:15
Updated : 2023-03-01 07:46
NVD link : CVE-2018-19577
Mitre link : CVE-2018-19577
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
gitlab
- gitlab