CVE-2019-18463 is an insecure permissions vulnerability affecting GitLab Community and Enterprise Editions through version 12.4. This medium-severity vulnerability, with a CVSS score of 4.3, allows a low-privileged attacker to achieve limited confidentiality impact without user interaction. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. While there is minimal community discussion, GitLab did release a security update addressing this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.4.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
<= 12.4.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.