CVE-2019-15734
Summary
| CVE | CVE-2019-15734 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-16 18:15:00 UTC |
| Updated | 2019-09-18 12:21:00 UTC |
| Description | An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Attacker is able to access Commit ID, Team Member name and comments when directly addressed (#64711) · Issues · GitLab.org / GitLab FOSS · GitLab | MISC | gitlab.com | Broken Link |
| GitLab Security Release: 12.2.3, 12.1.8, and 12.0.8 | GitLab | CONFIRM | about.gitlab.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.