MEDIUM
CVE-2019-12429
CVSS
6.5
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.
Summary dbcve.org
In GitLab 11.9 through 11.11, the milestone details page lacked proper authorization checks, allowing unprivileged users to view sensitive metadata (labels, status, merge request counts) of confidential issues that should have been restricted.
Mitigation
Upgrade GitLab to version 11.11.2 or later which contains the patched authorization logic that properly restricts access to confidential issue metadata on milestone pages.
EPSS Score
0.93%
Probability of exploitation in next 30 days
58.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.