An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-6551 An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-05T00:49:13.753Z

Reserved: 2019-08-26T00:00:00

Link: CVE-2019-15583

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-28T03:15:10.497

Modified: 2024-11-21T04:29:04.150

Link: CVE-2019-15583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.