First published: Fri May 17 2019(Updated: )
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.7.0<11.7.4 | |
GitLab | >=11.7.0<11.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7353 has been classified as a medium severity vulnerability.
To fix CVE-2019-7353, upgrade to GitLab Community or Enterprise Edition version 11.7.4 or later.
CVE-2019-7353 affects GitLab Community and Enterprise Editions from version 11.7.0 up to but not including 11.7.4.
CVE-2019-7353 is an Incorrect Access Control vulnerability.
Attackers exploiting CVE-2019-7353 could view confidential issue and merge request titles of other projects.