An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://about.gitlab.com/blog/categories/releases/ | vendor advisory |
https://about.gitlab.com/2018/12/31/security-release-gitlab-11-dot-6-dot-1-released/ | vendor advisory |