Medium severity4.3NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026
CVE-2019-6997
CVE-2019-6997
Description
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=10.7.0,<=10.8.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=10.7.0,<=10.8.7
- GitLab/Community and Enterprise Editiondescription
- Range: 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1
- Range: 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab-ce/issues/53858nvdExploitIssue TrackingThird Party Advisory
- about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.