Medium severity4.3NVD Advisory· Published Feb 14, 2020· Updated Jun 17, 2026
CVE-2019-15592
CVE-2019-15592
Description
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.2.0,<12.0.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.2.0,<12.0.8
- (no CPE)range: <=12.2.2
- GitLab/GitLabdescription
Patches
Vulnerability mechanics
References
2- about.gitlab.com/releases/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/nvdVendor Advisory
- hackerone.com/reports/588876nvdPermissions Required
News mentions
0No linked articles in our index yet.