MEDIUM

CVE-2019-12429

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
6.5

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to access labels, status and merge request counts of confidential issues via the milestone details page. It has Improper Access Control.

Summary dbcve.org

In GitLab 11.9 through 11.11, the milestone details page lacked proper authorization checks, allowing unprivileged users to view sensitive metadata (labels, status, merge request counts) of confidential issues that should have been restricted.

Mitigation

Upgrade GitLab to version 11.11.2 or later which contains the patched authorization logic that properly restricts access to confidential issue metadata on milestone pages.

EPSS Score

0.93%
Probability of exploitation in next 30 days
58.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE