An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.
References
Link | Resource |
---|---|
https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-dot-4-released/ | Release Notes Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab-ce/issues/56568 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-05-17T16:04:12
Updated: 2019-09-09T19:00:56
Reserved: 2019-02-04T00:00:00
Link: CVE-2019-7353
JSON object: View
NVD Information
Status : Modified
Published: 2019-05-17T17:29:00.920
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-7353
JSON object: View
Redhat Information
No data.
CWE