HIGH

CVE-2019-15725

Gitlab GitLab 2019-09-16 CVSS v3.1
CVSS
7.5

Description

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

Summary dbcve.org

An Insecure Direct Object Reference (IDOR) vulnerability in the epic notes API of GitLab Community and Enterprise Edition versions 12.0 through 12.2.1 allows authenticated users to access private milestones, labels, and other sensitive information that they should not have authorization to view.

Mitigation

Upgrade GitLab to version 12.2.2 or later to patch the IDOR vulnerability in the epic notes API.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

1.76%
Probability of exploitation in next 30 days
77th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE