CVE-2019-5487: GitLab
Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
Affected products
- GitLab GitLab: before 12.1.13 (fixed in 12.1.13); from 12.2.0, before 12.2.7 (fixed in 12.2.7); from 12.3.0, before 12.3.3 (fixed in 12.3.3)
Published 2019-12-18. Last modified 2026-06-17.