CVE-2019-7353

CRITICAL

GitLab CE/EE <11.7.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.

References (2)

Core 2
Core References
Issue Tracking x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/56568

Scores

CVSS v3 9.1
EPSS 0.0014
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-200
Status published
Products (1)
gitlab/gitlab 11.7.0 - 11.7.4 (2 CPE variants)
Published May 17, 2019
Tracked Since Feb 18, 2026