CVE-2018-19576
Description
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.
Summary dbcve.org
GitLab CE/EE versions 8.6 through 11.x before specific patched releases contain an access control bypass where Guest users can still modify or delete their own comments on issues after those issues have been changed to Confidential status. Guest users normally have read-only access to Confidential issues and should not be able to interact with them at all.
Mitigation
Upgrade GitLab to version 11.3.11, 11.4.8, or 11.5.1 or later. If immediate upgrade is not feasible, consider restricting Guest user access to projects containing sensitive issues until the patch can be applied.