CVE-2018-19580 affects all versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11. The vulnerability, categorized as CWE-20, is an improper input validation issue where GitLab fails to send a notification email to a user's old email address when an email address change is made. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and could lead to unauthorized information modification (I:L) if an attacker gains control of a user's account and changes the email without the original owner's knowledge. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
< 11.3.11CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.3.12, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.3.12, < 11.4.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.4.9, < 11.5.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.