HIGH

CVE-2018-19581

Gitlab GitLab 2019-07-10 CVSS v3.0
CVSS
7.5

Description

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

Summary dbcve.org

This is an Insecure Direct Object Reference (IDOR) vulnerability in GitLab EE where a Guest user (who should have read-only access) can set the weight attribute on issues they create. The application fails to properly authorize the weight field modification, allowing a low-privilege user to modify an attribute they should not have access to.

Mitigation

Upgrade GitLab to version 11.3.11, 11.4.8, 11.5.1 or later to receive the patched code that properly validates authorization for issue weight modifications.

Weakness (CWE)

CWE-285 Improper Authorization

EPSS Score

1.11%
Probability of exploitation in next 30 days
64.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE