A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR.
Solution:
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/414269 | issue tracking broken link |
https://hackerone.com/reports/2012073 | broken link exploit permissions required technical description |