CVE-2019-18461: GitLab

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.

Affected products

  • GitLab GitLab: from 11.3.0, up to and including 12.3.0

Published 2019-11-26. Last modified 2026-06-17.