First published: Wed Jul 10 2019(Updated: )
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.6.0<11.3.11 | |
GitLab | >=8.6.0<11.3.11 | |
GitLab | >=11.4.0<11.4.8 | |
GitLab | >=11.4.0<11.4.8 | |
GitLab | >=11.5.0<11.5.1 | |
GitLab | >=11.5.0<11.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19577 is classified as a medium severity vulnerability due to its potential impact on sensitive issue visibility.
To remediate CVE-2018-19577, upgrade GitLab to version 11.3.11 or later for the affected versions.
CVE-2018-19577 affects GitLab CE/EE versions from 8.6 up to but not including 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1.
CVE-2018-19577 exploits an incorrect access control vulnerability that allows unauthorized users to see the title and namespace of confidential issues.
You can determine vulnerability to CVE-2018-19577 by checking if your GitLab version is within the affected version range listed above.