Related Vulnerabilities: CVE-2018-18644  

A security issue has been found in gitlab versions prior to 11.4.3, where the Prometheus integration was vulnerable to an indirect object reference issue which allowed an unauthorized user to see private information. This information includes the project name, environment name, metric name, and metric query. Additionally, an unauthorized user could create false alarms.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue has been found in gitlab versions prior to 11.4.3, where the Prometheus integration was vulnerable to an indirect object reference issue which allowed an unauthorized user to see private information. This information includes the project name, environment name, metric name, and metric query. Additionally, an unauthorized user could create false alarms.

AVG-802 gitlab 11.4.0-1 11.4.3-2 High Not affected

https://about.gitlab.com/2018/10/29/security-release-gitlab-11-dot-4-dot-3-released/

Only affects Enterprise Edition, not for us.