CVE-2018-19577
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
Published
2019-07-10T15:15:12.133
Last Modified
2024-11-21T03:58:13.047
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 5.3 (MEDIUM)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
2.9
Weaknesses
Affected Vendors & Products
References
-
http://www.securityfocus.com/bid/109179
Broken Link, Third Party Advisory, VDB Entry
([email protected])
-
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/
Broken Link, Release Notes, Vendor Advisory
([email protected])
-
https://gitlab.com/gitlab-org/gitlab-ce/issues/52444
Issue Tracking, Vendor Advisory
([email protected])
-
http://www.securityfocus.com/bid/109179
Broken Link, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/
Broken Link, Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://gitlab.com/gitlab-org/gitlab-ce/issues/52444
Issue Tracking, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)