CVE-2018-19359 is an Incorrect Access Control vulnerability affecting GitLab Community and Enterprise Editions 8.9 and later, up to specific versions before 11.5.0-rc12, 11.4.6, and 11.3.10. This high-severity vulnerability (CVSS 8.8) allows an authenticated attacker to achieve high impact on confidentiality, integrity, and availability over the network with low attack complexity. While the vulnerability has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are public exploit modules or KEV entries available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.3.0, < 11.3.10CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.3.0, < 11.3.10CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.4.0, < 11.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.4.0, < 11.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.4.7, <= 11.4.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.