First published: Mon Sep 09 2019(Updated: )
An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.9.0<11.9.10 | |
GitLab | >=11.9.0<11.9.10 | |
GitLab | >=11.10.0<11.10.2 | |
GitLab | >=11.10.0<11.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11545 is considered a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2019-11545, update GitLab to version 11.9.10 or 11.10.2 or later.
CVE-2019-11545 is categorized as an Information Disclosure vulnerability.
CVE-2019-11545 affects users of GitLab Community Edition and Enterprise Edition versions before 11.9.10 and 11.10.2.
Exploitation of CVE-2019-11545 can lead to unauthorized users gaining access to private project namespaces.