CVE-2018-19582

MEDIUM

GitLab EE <11.4.8-11.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab-ee/issues/8180

Scores

CVSS v3 4.3
EPSS 0.0084
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
gitlab/gitlab 11.4.0 - 11.4.8
Published Jul 10, 2019
Tracked Since Feb 18, 2026