An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.
References
Link | Resource |
---|---|
https://about.gitlab.com/blog/categories/releases/ | Release Notes |
https://about.gitlab.com/releases/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/ | Release Notes Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-15T00:00:00
Updated: 2023-04-15T00:00:00
Reserved: 2018-09-25T00:00:00
Link: CVE-2018-17455
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-15T23:15:13.637
Modified: 2023-04-25T20:01:07.177
Link: CVE-2018-17455
JSON object: View
Redhat Information
No data.
CWE