CVE-2019-11605
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.
Summary dbcve.org
A small number of GitLab API endpoints improperly disclosed project information when accessed with read_user scoped tokens. The read_user scope is intended to provide limited access to user-specific data, but certain endpoints were returning project-related information that should not have been accessible at that privilege level.
Mitigation
Upgrade GitLab to version 11.8.10, 11.9.11, or 11.10.3 or later to resolve the improper information disclosure via read_user scoped API tokens.