Описание
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
Ссылки
- Vendor Advisory
- Release Notes
- Broken Link
- Vendor Advisory
- Release Notes
- Broken Link
Уязвимые конфигурации
Одно из
EPSS
5.8 Medium
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access C ...
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
EPSS
5.8 Medium
CVSS3
5 Medium
CVSS2