GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://about.gitlab.com/blog/categories/releases/ | release notes vendor advisory |
https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/ | release notes vendor advisory |