CVE-2018-19584

HIGH

GitLab EE <11.3.11-11.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

References (2)

Core 2
Core References
Exploit, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab-ce/issues/52522

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
gitlab/gitlab 11.0.0 - 11.3.11
Published Jul 10, 2019
Tracked Since Feb 18, 2026