CVE-2018-19496 is an incorrect access control vulnerability affecting GitLab Community and Enterprise Editions 10.x and 11.x before specific patch versions. This flaw allows a user with insufficient privileges to elevate a project milestone to a group milestone. With a CVSS score of 6.5 (Medium), this vulnerability can be exploited over the network with low attack complexity, requiring only low privileges to achieve high integrity impact by altering milestone scope. There is no confidentiality or availability impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there is limited community discussion and media coverage, GitLab did release security updates addressing this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.0.0, < 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.4.0, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.4.0, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.5.0, < 11.5.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.