CVE Vulnerabilities

CVE-2019-15592

Published: Feb 14, 2020 | Modified: Jan 03, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.2.0 (including) 12.0.8 (excluding)
Gitlab Gitlab 12.1.0 (including) 12.1.8 (excluding)
Gitlab Gitlab 12.2.0 (including) 12.2.3 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *
Gitlab Ubuntu xenial *

References