CVE-2019-13006

Source
https://cve.org/CVERecord?id=CVE-2019-13006
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13006.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-13006
Published
2020-03-10T17:15:12.783Z
Modified
2026-04-10T04:12:07.389983Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in GitLab Community and Enterprise Edition 9.0 and through 12.0.2. Users with access to issues, but not the repository were able to view the number of related merge requests on an issue. It has Incorrect Access Control.

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "9.0.0"
        },
        {
            "last_affected": "12.0.2"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "last_affected": "12.0.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13006.json"