VYPR
Low severity3.7NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026

CVE-2019-7176

CVE-2019-7176

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.9.0,<=8.17.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.9.0,<=8.17.8
    • (no CPE)range: 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2
  • GitLab/Community and Enterprise Editiondescription
  • Range: 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.