CVE-2019-11544 is an information disclosure vulnerability affecting GitLab Community and Enterprise Editions across versions 8.x, 9.x, 10.x, and 11.x prior to specific patch levels. Non-member users subscribed to notifications for internal projects with restricted issues and repositories could receive emails containing information about these restricted events. Rated Medium with a CVSS score of 4.3, this vulnerability has a low attack complexity and requires low privileges, but does not impact integrity or availability. The primary impact is the unauthorized disclosure of sensitive information. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's limited community discussion and media coverage, the vulnerability is not currently on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, <= 8.17.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 8.1.0, <= 8.17.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 9.0.0, <= 9.3.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 9.0.0, <= 9.3.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 10.0.0, <= 10.8.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.