CVE Vulnerabilities

CVE-2018-19359

Published: Apr 25, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab11.3.0 (including)11.3.10 (excluding)
GitlabGitlab11.4.0 (including)11.4.6 (excluding)
GitlabGitlab11.4.7 (including)11.4.9 (including)
GitlabGitlab11.5.0 (including)11.5.0 (including)
GitlabGitlab11.5.0-rc1 (including)11.5.0-rc1 (including)
GitlabGitlab11.5.0-rc10 (including)11.5.0-rc10 (including)
GitlabGitlab11.5.0-rc11 (including)11.5.0-rc11 (including)
GitlabGitlab11.5.0-rc2 (including)11.5.0-rc2 (including)
GitlabGitlab11.5.0-rc3 (including)11.5.0-rc3 (including)
GitlabGitlab11.5.0-rc4 (including)11.5.0-rc4 (including)
GitlabGitlab11.5.0-rc5 (including)11.5.0-rc5 (including)
GitlabGitlab11.5.0-rc6 (including)11.5.0-rc6 (including)
GitlabGitlab11.5.0-rc7 (including)11.5.0-rc7 (including)
GitlabGitlab11.5.0-rc8 (including)11.5.0-rc8 (including)
GitlabGitlab11.5.0-rc9 (including)11.5.0-rc9 (including)

References