CVE Vulnerabilities

CVE-2019-15590

Published: Jan 28, 2020 | Modified: Nov 02, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.1.0 (including) 12.1.14 (excluding)
Gitlab Gitlab 12.2.0 (including) 12.2.8 (excluding)
Gitlab Gitlab 12.3.0 (including) 12.3.5 (excluding)

References