An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/295662 | vendor advisory issue tracking exploit |
https://hackerone.com/reports/1064645 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22180.json | vendor advisory |