MEDIUM
CVE-2019-18456
CVSS
5.3
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).
Weakness (CWE)
CWE-732
Incorrect Permission Assignment
EPSS Score
0.88%
Probability of exploitation in next 30 days
57.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.