CVE-2019-12434

Source
https://cve.org/CVERecord?id=CVE-2019-12434
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12434.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-12434
Published
2020-03-10T14:15:11Z
Modified
2026-08-27T18:53:10Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "10.6.0"
        },
        {
            "last_affected": "11.11.0"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12434.json"