CVE-2019-15577: Infoleak
Published Dec 18, 2019
·Updated
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
Affected Software
6 affected components
GitLab GitLab<12.1.12
GitLab GitLab<12.1.12
GitLab GitLab>=12.2.0<12.2.6
GitLab GitLab>=12.2.0<12.2.6
GitLab GitLab>=12.3.0<12.3.2
GitLab GitLab>=12.3.0<12.3.2
Event History
Dec 18, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15577?
The CVE-2019-15577 vulnerability is rated as having a medium severity level due to possible information disclosure.
2
How do I fix CVE-2019-15577?
To mitigate CVE-2019-15577, upgrade GitLab to versions 12.3.2, 12.2.6, or 12.1.12 or later.
3
What is the impact of CVE-2019-15577?
The impact of CVE-2019-15577 is that it allows unauthorized users to view project milestones from groups they should not have access to.
4
Which versions of GitLab are affected by CVE-2019-15577?
Affected versions of GitLab include all versions prior to 12.3.2, 12.2.6, and 12.1.12.
5
Is CVE-2019-15577 present in both GitLab CE and EE?
Yes, CVE-2019-15577 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) for the specified versions.