CVE-2018-19578: Medium severity gitlab vulnerability
Published Jul 10, 2019
·Updated
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
Affected Software
1 affected component
GitLab GitLab>=11.5.0<11.5.1
Event History
Jul 10, 2019
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19578?
CVE-2018-19578 is rated as a medium severity vulnerability due to its potential to expose sensitive information to unauthorized users.
2
How do I fix CVE-2018-19578?
To fix CVE-2018-19578, upgrade GitLab EE from version 11.5.0 to 11.5.1 or later.
3
Who is affected by CVE-2018-19578?
Users with Reporter privileges on GitLab EE versions prior to 11.5.1 are affected by CVE-2018-19578.
4
What is the impact of CVE-2018-19578?
CVE-2018-19578 allows unauthorized users to view the Jaeger Tracing Operations page, potentially leaking sensitive operations data.
5
When was CVE-2018-19578 disclosed?
CVE-2018-19578 was disclosed in November 2018 with the release of GitLab 11.5.1.