CVE-2018-19494
Summary
| CVE | CVE-2018-19494 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-10 15:15:00 UTC |
| Updated | 2019-07-11 16:40:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 11.5.1, 11.4.8, and 11.3.11 | GitLab | CONFIRM | about.gitlab.com | Release Notes, Vendor Advisory |
| Read Name of any private groups (#51262) · Issues · GitLab.org / GitLab FOSS · GitLab | MISC | gitlab.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.