First published: Wed Dec 18 2019(Updated: )
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <12.1.12 | |
GitLab | <12.1.12 | |
GitLab | >=12.2.0<12.2.6 | |
GitLab | >=12.2.0<12.2.6 | |
GitLab | >=12.3.0<12.3.2 | |
GitLab | >=12.3.0<12.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2019-15577 vulnerability is rated as having a medium severity level due to possible information disclosure.
To mitigate CVE-2019-15577, upgrade GitLab to versions 12.3.2, 12.2.6, or 12.1.12 or later.
The impact of CVE-2019-15577 is that it allows unauthorized users to view project milestones from groups they should not have access to.
Affected versions of GitLab include all versions prior to 12.3.2, 12.2.6, and 12.1.12.
Yes, CVE-2019-15577 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) for the specified versions.