CVE-2019-15738: Infoleak
Published Sep 16, 2019
·Updated
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.
Affected Software
6 affected components
GitLab GitLab>=12.0.0<12.0.8
GitLab GitLab>=12.0.0<12.0.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.1.0<12.1.8
GitLab GitLab>=12.2.0<12.2.3
GitLab GitLab>=12.2.0<12.2.3
Event History
Sep 16, 2019
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15738?
CVE-2019-15738 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-15738?
To fix CVE-2019-15738, upgrade your GitLab instance to version 12.2.3 or later.
3
What products are affected by CVE-2019-15738?
CVE-2019-15738 affects GitLab Community and Enterprise Editions from versions 12.0 to 12.2.1.
4
What type of information is disclosed in CVE-2019-15738?
CVE-2019-15738 can lead to the disclosure of merge request IDs via email.
5
When was CVE-2019-15738 disclosed?
CVE-2019-15738 was disclosed in August 2019.