CVE-2019-15725
Summary
| CVE | CVE-2019-15725 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-16 17:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information. |
Risk And Classification
Problem Types: CWE-639
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 12.2.3, 12.1.8, and 12.0.8 | GitLab | MISC | about.gitlab.com | Release Notes, Vendor Advisory |
| IDOR in epic notes api, also reveals historical information if it was promoted from issue (#11431) · Issues · GitLab.org / GitLab · GitLab | MISC | gitlab.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.