CVE-2018-19577: Medium severity gitlab vulnerability
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19577?
CVE-2018-19577 is classified as a medium severity vulnerability due to its potential impact on sensitive issue visibility.
How do I fix CVE-2018-19577?
To remediate CVE-2018-19577, upgrade GitLab to version 11.3.11 or later for the affected versions.
What versions are affected by CVE-2018-19577?
CVE-2018-19577 affects GitLab CE/EE versions from 8.6 up to but not including 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1.
What does CVE-2018-19577 exploit?
CVE-2018-19577 exploits an incorrect access control vulnerability that allows unauthorized users to see the title and namespace of confidential issues.
How can I determine if my GitLab instance is vulnerable to CVE-2018-19577?
You can determine vulnerability to CVE-2018-19577 by checking if your GitLab version is within the affected version range listed above.