CVE-2019-15583: Infoleak
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15583?
CVE-2019-15583 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2019-15583?
To mitigate CVE-2019-15583, upgrade GitLab to version 12.3.2 or later, 12.2.6 or later, or 12.1.12 or later.
What is the impact of CVE-2019-15583 on GitLab?
CVE-2019-15583 allows unauthorized disclosure of private labels and namespaces when issues are moved from private to public projects.
Which versions of GitLab are affected by CVE-2019-15583?
CVE-2019-15583 affects GitLab Community Edition and Enterprise Edition versions earlier than 12.1.12, 12.2.6, and 12.3.2.
Is user action required to resolve CVE-2019-15583?
Yes, users must take action by upgrading to the patched versions of GitLab to resolve CVE-2019-15583.