PT-2019-18558 · Gitlab · Gitlab Ce/Ee+1

Xanbanx

·

Publicado

2019-05-17

·

Atualizado

2020-08-24

·

CVE-2019-7353

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab Community and Enterprise Edition versions 11.7.x through 11.7.3
Description An issue of incorrect access control was discovered, allowing users to view confidential issues and merge request titles of other projects due to an authorization problem.
Recommendations For GitLab Community and Enterprise Edition versions 11.7.x through 11.7.3, update to version 11.7.4 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7353

Produtos afetados

Gitlab
Gitlab Ce/Ee