Improper Authorization in Gitlab Community Edition - CVE-2018-19584

 

Improper Authorization in Gitlab Community Edition - CVE-2018-19584

Published: July 10, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30995
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-19584
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: GitLab, Inc
Affected software:
Gitlab Community Edition

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.


How to mitigate CVE-2018-19584

Install update from vendor's website.

Sources