HIGH
CVE-2019-15725
CVSS
7.5
Description
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.
Summary dbcve.org
An Insecure Direct Object Reference (IDOR) vulnerability in the epic notes API of GitLab Community and Enterprise Edition versions 12.0 through 12.2.1 allows authenticated users to access private milestones, labels, and other sensitive information that they should not have authorization to view.
Mitigation
Upgrade GitLab to version 12.2.2 or later to patch the IDOR vulnerability in the epic notes API.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
1.76%
Probability of exploitation in next 30 days
77th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.