CVE-2018-20507

MEDIUM

GitLab 11.2.0-11.4.12, 11.5.0-11.5.5, 11.6.0 - Unauthenticated Incorrect Access Control

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 29.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-306
Status published
Products (1)
gitlab/gitlab 11.2.0 - 11.4.13 (2 CPE variants)
Published Dec 30, 2019
Tracked Since Feb 18, 2026