CVE-2019-18461

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/11/2019
Last modified:
03/12/2019

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 11.3.0 (including) 12.3.0 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 11.3.0 (including) 12.3.0 (including)