CVE-2018-18644

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
A security issue has been found in gitlab versions prior to 11.4.3, where the Prometheus integration was vulnerable to an indirect object reference issue which allowed an unauthorized user to see private information. This information includes the project name, environment name, metric name, and metric query. Additionally, an unauthorized user could create false alarms.
Group Package Affected Fixed Severity Status Ticket
AVG-802 gitlab 11.4.0-1 11.4.3-2 High Not affected
References
https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/
Notes
Only affects Enterprise Edition, not for us.