PT-2020-9315 · Gitlab · Gitlab Ce/Ee+1
Ashish_R_Padelkar
·
Published
2020-03-10
·
Updated
2021-07-21
·
CVE-2019-12429
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GitLab Community and Enterprise Edition versions 11.9 through 11.11
Description:
An issue was discovered that allows unprivileged users to access labels, status, and merge request counts of confidential issues via the milestone details page. This is due to improper access control.
Recommendations:
For GitLab Community and Enterprise Edition versions 11.9 through 11.11, update to a version that contains a fix for this issue to prevent unprivileged users from accessing sensitive information about confidential issues.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee