An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-10T14:50:43

Updated: 2024-08-05T11:37:11.503Z

Reserved: 2018-11-23T00:00:00

Link: CVE-2018-19496

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-07-10T15:15:12.057

Modified: 2019-07-11T17:15:34.653

Link: CVE-2018-19496

cve-icon Redhat

No data.