An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.
Solution:
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/416482 | exploit issue tracking permissions required |
https://hackerone.com/reports/2033561 | exploit permissions required technical description |
https://gitlab.com/gitlab-org/gitlab/-/issues/417284 | exploit issue tracking permissions required |
https://hackerone.com/reports/2041385 | exploit permissions required technical description |