CVE-2019-15590
published 2020-01-28CVE-2019-15590: An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.11%
62.0th percentile
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | — | — |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 12.1.0 < 12.1.14 | 12.1.14 |
| gitlab | gitlab | >= 12.2.0 < 12.2.8 | 12.2.8 |
| gitlab | gitlab | >= 12.3.0 < 12.3.5 | 12.3.5 |
| gitlab | gitlab_ee | — | — |
| gitlab | gitlab_ee | — | — |
| gitlab | gitlab_ee | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
CVE-2019-15590: An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge
vendor_gitlab·2020-01-28·CVSS 7.5
CVE-2019-15590 [HIGH] CWE-284 CVE-2019-15590: An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge
CVE-2019-15590: An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
Debian
CVE-2019-15590: gitlab - An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab C...
vendor_debian·2019·CVSS 7.5
CVE-2019-15590 [HIGH] CVE-2019-15590: gitlab - An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab C...
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
Scope: local
sid: resolved
GHSA
GHSA-83w3-58xf-86mr: An access control issue exists in < 12
ghsa_unreviewed·2022-05-24
CVE-2019-15590 [MEDIUM] GHSA-83w3-58xf-86mr: An access control issue exists in < 12
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-28
Published