CVE-2019-19629

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2020
Last modified:
21/07/2021

Description

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 10.5.0 (including) 12.3.8 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.4.0 (including) 12.4.5 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.5.0 (including) 12.5.3 (including)