PT-2020-9315 · Gitlab · Gitlab Ce/Ee+1

Ashish_R_Padelkar

·

Published

2020-03-10

·

Updated

2021-07-21

·

CVE-2019-12429

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab Community and Enterprise Edition versions 11.9 through 11.11
Description: An issue was discovered that allows unprivileged users to access labels, status, and merge request counts of confidential issues via the milestone details page. This is due to improper access control.
Recommendations: For GitLab Community and Enterprise Edition versions 11.9 through 11.11, update to a version that contains a fix for this issue to prevent unprivileged users from accessing sensitive information about confidential issues.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-12429

Affected Products

Gitlab
Gitlab Ce/Ee