An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.
References
Link | Resource |
---|---|
https://about.gitlab.com/blog/categories/releases/ | Release Notes |
https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/ | Release Notes Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-15T00:00:00
Updated: 2023-04-15T00:00:00
Reserved: 2018-09-25T00:00:00
Link: CVE-2018-17449
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-15T23:15:13.400
Modified: 2023-04-25T20:27:11.613
Link: CVE-2018-17449
JSON object: View
Redhat Information
No data.
CWE