CVE-2019-6790

MEDIUM

GitLab 8.14.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Unauthenticated Merge Request List Exposure

Title source: llm
STIX 2.1

Description

An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests.

References (2)

Core 2
Core References
Issue Tracking x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/51328

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (1)
gitlab/gitlab 8.14.0 - 11.5.8 (2 CPE variants)
Published May 17, 2019
Tracked Since Feb 18, 2026