An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.
Solution:
The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/525374 | issue tracking permissions required |
https://hackerone.com/reports/3030586 | exploit permissions required technical description |