VYPR
High severity7.5NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026

CVE-2019-11605

CVE-2019-11605

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

Affected products

6
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.8.0,<11.8.10
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.8.0,<11.8.10
    • (no CPE)range: 11.8.x < 11.8.10, 11.9.x < 11.9.11, 11.10.x < 11.10.3
  • GitLab/Community and Enterprise Editiondescription
  • Range: 11.8.x < 11.8.10, 11.9.x < 11.9.11, 11.10.x < 11.10.3
  • Range: 11.8.x < 11.8.10, 11.9.x < 11.9.11, 11.10.x < 11.10.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.