CVE-2019-18460: GitLab
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.
Affected products
- GitLab GitLab: from 8.15.0, up to and including 12.4.0
Published 2019-11-26. Last modified 2026-06-17.