Vulnerability Description
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view confidential issue and merge request titles of other projects.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.7.0, < 11.7.4 |
Related Weaknesses (CWE)
References
- https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-doRelease NotesVendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/56568
- https://about.gitlab.com/2019/02/05/critical-security-release-gitlab-11-dot-7-doRelease NotesVendor Advisory
- https://gitlab.com/gitlab-org/gitlab-ce/issues/56568
FAQ
What is CVE-2019-7353?
CVE-2019-7353 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view c...
How severe is CVE-2019-7353?
CVE-2019-7353 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-7353?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.