CVE-2019-15590: GitLab

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

Affected products

  • GitLab GitLab: from 12.1.0, before 12.1.14 (fixed in 12.1.14); from 12.2.0, before 12.2.8 (fixed in 12.2.8); from 12.3.0, before 12.3.5 (fixed in 12.3.5)

Published 2020-01-28. Last modified 2026-06-17.