CVE-2019-5466
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.0%
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
Affected products
n/a · GitLab CE/EE