An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab-ce/issues/63124 | broken link |
https://about.gitlab.com/2019/08/29/security-release-gitlab-12-dot-2-dot-3-released/ | release notes vendor advisory |