HIGH
CVE-2018-19581
CVSS
7.5
Description
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.
Summary dbcve.org
This is an Insecure Direct Object Reference (IDOR) vulnerability in GitLab EE where a Guest user (who should have read-only access) can set the weight attribute on issues they create. The application fails to properly authorize the weight field modification, allowing a low-privilege user to modify an attribute they should not have access to.
Mitigation
Upgrade GitLab to version 11.3.11, 11.4.8, 11.5.1 or later to receive the patched code that properly validates authorization for issue weight modifications.
Weakness (CWE)
CWE-285
Improper Authorization
EPSS Score
1.11%
Probability of exploitation in next 30 days
64.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.