First published: Mon Sep 16 2019(Updated: )
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.0.0<12.0.8 | |
GitLab | >=12.0.0<12.0.8 | |
GitLab | >=12.1.0<12.1.8 | |
GitLab | >=12.1.0<12.1.8 | |
GitLab | >=12.2.0<12.2.3 | |
GitLab | >=12.2.0<12.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15725 has a medium severity level due to its potential to expose sensitive data.
To fix CVE-2019-15725, upgrade GitLab to version 12.2.3 or later.
CVE-2019-15725 can disclose private milestones, labels, and other sensitive information through the epic notes API.
GitLab Community and Enterprise Editions from versions 12.0.0 to 12.2.1 are affected by CVE-2019-15725.
Yes, CVE-2019-15725 exploits an Insecure Direct Object Reference (IDOR) that allows unauthorized users to access private data.