Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/212911 | issue tracking patch vendor advisory exploit |
https://hackerone.com/reports/833334 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22172.json | vendor advisory |