CVE-2019-19629: GitLab
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
Affected products
- GitLab GitLab: from 10.5.0, up to and including 12.3.8; from 12.4.0, up to and including 12.4.5; from 12.5.0, up to and including 12.5.3
Published 2020-01-05. Last modified 2026-06-17.