CVE-2019-12432: Infoleak
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12432?
CVE-2019-12432 is considered a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2019-12432?
To fix CVE-2019-12432, upgrade to GitLab versions 11.11.1 or later.
Who is affected by CVE-2019-12432?
CVE-2019-12432 affects non-member users who subscribed to issue notifications in GitLab Community and Enterprise Edition versions 8.13 through 11.11.
What type of vulnerability is CVE-2019-12432?
CVE-2019-12432 is categorized as an information disclosure vulnerability.
What can an attacker gain from CVE-2019-12432?
An attacker exploiting CVE-2019-12432 can access the titles of confidential issues through the unsubscription page.