CVE-2018-19582

MEDIUM

GitLab EE <11.4.8-11.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab-ee/issues/8180

Scores

CVSS v3 4.3
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
gitlab/gitlab 11.4.0 - 11.4.8
Published Jul 10, 2019
Tracked Since Feb 18, 2026