CVE-2018-17455 (retired)

Priority
Description
The merge request approvals component contained an insecure direct
object reference vulnerability which resulted in disclosure of private
group names, avatars, LDAP settings, and descriptions.
Package
Upstream:released (11.3.1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
More Information

Updated: 2019-03-26 12:27:14 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)