CVE-2018-17449
Description
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.
Summary dbcve.org
GitLab versions before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1 contain an Insecure Direct Object Reference (IDOR) vulnerability in the events API. Remote attackers can access sensitive information including issues, comments, and project titles by manipulating object references in API requests, bypassing intended access controls.
Mitigation
Upgrade GitLab to version 11.1.7, 11.2.4, 11.3.1 or later. Verify that the events API now properly enforces authorization checks before returning sensitive project data.