An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/ | release notes vendor advisory |
https://gitlab.com/gitlab-org/gitlab-ce/issues/54867 | third party advisory exploit |