CVE-2019-12434: GitLab

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.

Affected products

  • GitLab GitLab: from 10.6.0, up to and including 11.11.0

Published 2020-03-10. Last modified 2026-06-17.