Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7492

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

A flaw was found in GitLab. Under certain conditions, an unauthenticated user could determine the existence of a private project. This information disclosure is possible due to improper authorization controls on cross-project reference pages. This vulnerability allows an attacker to gain sensitive information about private projects.

Отчет

Red Hat does not ship or distribute GitLab Community Edition (CE) or Enterprise Edition (EE), the products affected by this flaw. This CVE was matched to Red Hat container images (OpenShift Console, OpenShift Pipelines Console Plugin) solely because they bundle an unrelated third-party npm client library named "gitlab" (node-gitlab, github.com/jdalrymple/node-gitlab), a REST API wrapper for calling a remote GitLab server. This client library does not contain the GitLab server-side authorization logic affected by this vulnerability, and Red Hat products are not affected.

Меры по смягчению последствий

Not applicable; Red Hat products are not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2498285gitlab-ee: gitlab: GitLab: Information disclosure of private project existence via improper authorization

EPSS

Процентиль: 17%
0.00254
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

CVSS3: 4.3
nvd
22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

CVSS3: 4.3
github
22 дня назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

CVSS3: 4.3
fstec
23 дня назад

Уязвимость механизма отображения обсуждений коммитов и межпроектных ссылок программной платформы на базе git для совместной работы над кодом GitLab CE/EE, позволяющая нарушителю нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 17%
0.00254
Низкий

5.3 Medium

CVSS3