GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-14T21:27:56

Updated: 2020-02-14T21:27:56

Reserved: 2019-08-26T00:00:00


Link: CVE-2019-15592

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-14T22:15:10.360

Modified: 2024-01-03T18:55:45.153


Link: CVE-2019-15592

JSON object: View

cve-icon Redhat Information

No data.