An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-01-28T02:31:05

Updated: 2024-08-05T00:49:13.635Z

Reserved: 2019-08-26T00:00:00

Link: CVE-2019-15590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-01-28T03:15:10.717

Modified: 2021-11-02T19:16:05.343

Link: CVE-2019-15590

cve-icon Redhat

No data.