CVE-2018-19578
Description
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
Summary dbcve.org
GitLab EE version 11.5 contains an Insecure Direct Object Reference (IDOR) vulnerability in the Jaeger Tracing feature. Users with Reporter-level permissions (typically read-only access) can view the Jaeger Tracing Operations page, which should be restricted to higher-privileged users. This is a broken access control vulnerability where object references are not properly validated against the user's authorization level.
Mitigation
Upgrade GitLab EE to version 11.5.1 or later, which contains the fix for this access control bypass. Alternatively, if immediate upgrade is not possible, consider restricting Reporter-level access to sensitive tracing features until the patch can be applied.