Improper Authorization in Gitlab Community Edition - CVE-2018-19584
Published: July 10, 2019 / Updated: July 17, 2020
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.