CVE-2019-13011 is a medium-severity vulnerability affecting GitLab Enterprise Edition versions 8.11.0 through 12.0.2. It allows an authenticated user with project access, but without repository access, to brute-force and enumerate merge request template names due to excessive algorithmic complexity. The CVSS score of 4.3 indicates a low impact on confidentiality with no integrity or availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond the vendor's security release announcement.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.11.0, <= 12.0.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.