In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/33734 | broken link |
https://hackerone.com/reports/698068 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39898.json | vendor advisory |