CVE-2018-19577

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab-ce/issues/52444 Issue Tracking Vendor Advisory
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/ Broken Link Release Notes Vendor Advisory
http://www.securityfocus.com/bid/109179 Broken Link Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Information

Published : 2019-07-10 08:15

Updated : 2023-03-01 07:46


NVD link : CVE-2018-19577

Mitre link : CVE-2018-19577


JSON object : View

CWE
CWE-284

Improper Access Control

Advertisement

dedicated server usa

Products Affected

gitlab

  • gitlab