An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
Solution:
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/415131 | vendor advisory issue tracking |