LiveActive security incident?Get immediate response
CVE Record

CVE-2018-19359: GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incor...

GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE describes an incorrect access control flaw in GitLab Community and Enterprise Edition. The public bundle does not explain the exact action an unauthorized user could perform, so business impact cannot be scoped precisely. Treat exposed self-managed GitLab instances in the affected version range as requiring urgent version review and vendor-guided update.

Executive priority

Prioritize verification and remediation for externally reachable GitLab systems. The limited public detail prevents precise impact scoring, but access control issues in source-code platforms can affect sensitive code, credentials, and delivery pipelines.

Technical view

Affected versions are GitLab CE/EE 8.9 and later before 11.5.0-rc12, 11.4.6, and 11.3.10. The CVE classifies the issue only as incorrect access control. No CVSS, CWE, exploit details, or affected component specifics are included in the provided sources.

Likely exposure

Exposure is most likely on self-managed GitLab CE or EE deployments running the affected versions, especially internet-accessible systems. The source bundle does not identify SaaS exposure, prerequisites, permissions, or a vulnerable feature path.

Exploitation context

The provided sources do not report active exploitation, and the CVE is not marked KEV. No public exploit status is supported by the bundle. Absence of evidence is not proof of safety; it only limits what can be stated confidently.

Researcher notes

The bundle names product family and fixed version boundaries, but omits vulnerable endpoint, permissions required, root cause, and exploitability detail. Validation should stay version-based unless GitLab’s linked advisory or issue provides additional safe, vendor-confirmed checks.

Mitigation direction

  • Inventory all GitLab CE and EE instances and record exact versions.
  • Upgrade affected installations to 11.5.0-rc12, 11.4.6, 11.3.10, or later vendor guidance.
  • Prioritize internet-facing and business-critical GitLab systems first.
  • Review GitLab’s critical security release advisory before change planning.
  • If upgrade timing is constrained, check GitLab guidance for supported interim mitigations.

Validation and detection

  • Confirm each GitLab instance version is outside the affected range.
  • Verify the applied package or container image matches a fixed GitLab release.
  • Review access-control-sensitive logs for unusual repository, project, or user activity.
  • Confirm vulnerability scanners map findings to the actual installed GitLab version.
  • Document remediation status for each self-managed GitLab environment.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-19359 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.