An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-06T20:18:51.858Z
Reserved: 2018-09-25T00:00:00.000Z
Link: CVE-2018-17455

Updated: 2024-08-05T10:47:04.910Z

Status : Modified
Published: 2023-04-15T23:15:13.637
Modified: 2025-02-06T21:15:11.797
Link: CVE-2018-17455

No data.