CVE-2019-19629: GitLab

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

Affected products

  • GitLab GitLab: from 10.5.0, up to and including 12.3.8; from 12.4.0, up to and including 12.4.5; from 12.5.0, up to and including 12.5.3

Published 2020-01-05. Last modified 2026-06-17.