GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://about.gitlab.com/releases/categories/releases/ | release notes vendor advisory |
https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/ | release notes vendor advisory |
https://www.debian.org/security/2020/dsa-4691 | third party advisory vendor advisory |