CVE-2019-6782 is an information disclosure vulnerability affecting GitLab Community and Enterprise Editions before versions 11.5.8, 11.6.6, and 11.7.1. This flaw allows unauthorized viewing of contributed project information from a private profile due to an authorization issue. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a significant risk. It can be exploited remotely over the network with low attack complexity, requiring no user interaction, and results in high confidentiality impact without affecting integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. While there is limited community discussion and media coverage, GitLab has released security updates to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.3.0, < 11.5.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.3.0, < 11.5.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.6.0, < 11.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.6.0, < 11.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.7.0, < 11.7.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.