CVE-2018-19577Improper Access Control in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 51.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDgitlab/gitlab8.6.011.3.11+2
debiandebian/gitlab< gitlab 11.3.11+dfsg-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-2jq2-4fqx-jx67: Gitlab CE/EE, versions 82022-05-24

📋Vendor Advisories

2
GitLab
CVE-2018-19577: Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulner2019-07-10
Debian
CVE-2018-19577: gitlab - Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11...2018