CVE-2018-19580 (NVD)

2019-07-10

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

Products Gitlab
Type Improper Input Validation (CWE-20)
First patch - None (likely due to unavailable code)
Links https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/
https://gitlab.com/gitlab-org/gitlab-ce/issues/39809