In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/338062 | broken link |
https://hackerone.com/reports/1294017 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39889.json | vendor advisory |