AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-17449

HIGH · CVSS 7.5 EPSS 0.84%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-04-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-17449
Severity
HIGH
CVSS
7.5
EPSS
0.84%
GitLab

Original NVD Description

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, comments, and project titles via events API insecure direct object reference.