First published: Wed Jul 10 2019(Updated: )
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.5.0<11.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19578 is rated as a medium severity vulnerability due to its potential to expose sensitive information to unauthorized users.
To fix CVE-2018-19578, upgrade GitLab EE from version 11.5.0 to 11.5.1 or later.
Users with Reporter privileges on GitLab EE versions prior to 11.5.1 are affected by CVE-2018-19578.
CVE-2018-19578 allows unauthorized users to view the Jaeger Tracing Operations page, potentially leaking sensitive operations data.
CVE-2018-19578 was disclosed in November 2018 with the release of GitLab 11.5.1.