Unrated severityNVD Advisory· Published Dec 18, 2019· Updated Aug 4, 2024
CVE-2019-5487
CVE-2019-5487
Description
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
Affected products
2- Range: <12.3.3, <12.2.7, <12.1.13
- Range: 12.3.3, 12.2.7, 12.1.13
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- hackerone.com/reports/692252mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.