An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://about.gitlab.com/releases/2019/07/29/security-release-gitlab-12-dot-1-dot-2-released/ | release notes patch vendor advisory |
https://hackerone.com/reports/584534 | permissions required |
https://gitlab.com/gitlab-org/gitlab-ce/issues/62070 | exploit vendor advisory |