HIGH

CVE-2018-19576

Gitlab GitLab 2019-07-10 CVSS v3.0
CVSS
8.1

Description

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

Summary dbcve.org

GitLab CE/EE versions 8.6 through 11.x before specific patched releases contain an access control bypass where Guest users can still modify or delete their own comments on issues after those issues have been changed to Confidential status. Guest users normally have read-only access to Confidential issues and should not be able to interact with them at all.

Mitigation

Upgrade GitLab to version 11.3.11, 11.4.8, or 11.5.1 or later. If immediate upgrade is not feasible, consider restricting Guest user access to projects containing sensitive issues until the patch can be applied.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

1.18%
Probability of exploitation in next 30 days
66.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE