CVE-2019-15578: Infoleak
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15578?
CVE-2019-15578 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-15578?
To address CVE-2019-15578, upgrade to GitLab version 12.3.2 or later, 12.2.6 or later, or 12.1.12 or later.
What type of information is leaked by CVE-2019-15578?
CVE-2019-15578 discloses the path of a previously public project in unsubscribe email links.
Which versions of GitLab are affected by CVE-2019-15578?
CVE-2019-15578 affects GitLab Community Edition and Enterprise Edition versions prior to 12.3.2, 12.2.6, and 12.1.12.
What are the implications of CVE-2019-15578 for GitLab users?
Users of affected GitLab versions may unintentionally expose the paths of private projects through email notifications.