An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://hackerone.com/reports/636560 | issue tracking exploit third party advisory |