VulnerabilityModified
CVE-2018-19577
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
MEDIUM 5.3EPSS 2.15%
Does this matter?
Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.
Description
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- gitlab/gitlab
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/109179Broken Link, Third Party Advisory, VDB Entry
- https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/Broken Link, Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/52444Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/109179Broken Link, Third Party Advisory, VDB Entry
- https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/Broken Link, Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/52444Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.