{"api_version":"1","generated_at":"2026-07-23T14:50:39+00:00","cve":"CVE-2018-19577","urls":{"html":"https://cve.report/CVE-2018-19577","api":"https://cve.report/api/cve/CVE-2018-19577.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-19577","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-19577"},"summary":{"title":"CVE-2018-19577","description":"Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-10 15:15:00","updated_at":"2023-03-01 15:46:00"},"problem_types":["CWE-284"],"metrics":[],"references":[{"url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","name":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"GitLab Security Release: 11.5.1, 11.4.8, and 11.3.11 | GitLab","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/109179","name":"109179","refsource":"BID","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444","name":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444","refsource":"MISC","tags":["Issue Tracking","Vendor Advisory"],"title":"Exposure of Private Project's Confidential Issues' title and Namespace in Commit Message (#52444) · Issues · GitLab.org / GitLab FOSS · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-19577","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19577","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"19577","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19577","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19577","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19577","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-19577","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444","url":"https://gitlab.com/gitlab-org/gitlab-ce/issues/52444"},{"refsource":"CONFIRM","name":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/","url":"https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/"},{"refsource":"BID","name":"109179","url":"http://www.securityfocus.com/bid/109179"}]}},"nvd":{"publishedDate":"2019-07-10 15:15:00","lastModifiedDate":"2023-03-01 15:46:00","problem_types":["CWE-284"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.6.0","versionEndExcluding":"11.3.11","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"19577","Ordinal":"137957","Title":"CVE-2018-19577","CVE":"CVE-2018-19577","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"19577","Ordinal":"1","NoteData":"Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"19577","Ordinal":"2","NoteData":"2019-07-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"19577","Ordinal":"3","NoteData":"2019-07-16","Type":"Other","Title":"Modified"}]}}}