Description
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6548 | An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted. |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/667408 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T00:49:13.790Z
Reserved: 2019-08-26T00:00:00.000Z
Link: CVE-2019-15580
No data.
Status : Modified
Published: 2019-12-18T21:15:11.977
Modified: 2024-11-21T04:29:03.750
Link: CVE-2019-15580
No data.
OpenCVE Enrichment
No data.
EUVD