CVE-2019-7353: Infoleak
Published May 17, 2019
·Updated
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.
Affected Software
2 affected components
GitLab GitLab>=11.7.0<11.7.4
GitLab GitLab>=11.7.0<11.7.4
Event History
May 17, 2019
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-7353?
CVE-2019-7353 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-7353?
To fix CVE-2019-7353, upgrade to GitLab Community or Enterprise Edition version 11.7.4 or later.
3
What does CVE-2019-7353 affect?
CVE-2019-7353 affects GitLab Community and Enterprise Editions from version 11.7.0 up to but not including 11.7.4.
4
What type of vulnerability is CVE-2019-7353?
CVE-2019-7353 is an Incorrect Access Control vulnerability.
5
What can attackers do with CVE-2019-7353?
Attackers exploiting CVE-2019-7353 could view confidential issue and merge request titles of other projects.