An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-06T20:18:51.858Z
Reserved: 2018-09-25T00:00:00.000Z
Link: CVE-2018-17455

Updated: 2024-08-05T10:47:04.910Z

Status : Modified
Published: 2023-04-15T23:15:13.637
Modified: 2025-02-06T21:15:11.797
Link: CVE-2018-17455

No data.

No data.