{"api_version":"1","generated_at":"2026-07-23T08:15:33+00:00","cve":"CVE-2018-19494","urls":{"html":"https://cve.report/CVE-2018-19494","api":"https://cve.report/api/cve/CVE-2018-19494.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-19494","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-19494"},"summary":{"title":"CVE-2018-19494","description":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-10 15:15:00","updated_at":"2019-07-11 16:40:00"},"problem_types":["CWE-284"],"metrics":[],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","name":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"GitLab Security Release: 11.5.1, 11.4.8, and 11.3.11 | GitLab","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262","name":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262","refsource":"MISC","tags":["Issue Tracking","Vendor Advisory"],"title":"Read Name of any private groups (#51262) · Issues · GitLab.org / GitLab FOSS · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-19494","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19494","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"19494","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19494","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19494","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19494","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-19494","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262","url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/51262"},{"refsource":"CONFIRM","name":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/"}]}},"nvd":{"publishedDate":"2019-07-10 15:15:00","lastModifiedDate":"2019-07-11 16:40:00","problem_types":["CWE-284"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.3.11","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"19494","Ordinal":"136575","Title":"CVE-2018-19494","CVE":"CVE-2018-19494","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"19494","Ordinal":"1","NoteData":"An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"19494","Ordinal":"2","NoteData":"2019-07-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"19494","Ordinal":"3","NoteData":"2019-07-10","Type":"Other","Title":"Modified"}]}}}