An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://about.gitlab.com/2019/04/29/security-release-gitlab-11-dot-10-dot-2-released/ | release notes vendor advisory |
https://gitlab.com/gitlab-org/gitlab-ce/issues/58939 | exploit vendor advisory |