Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.
Related CPE's
a
gitlab
gitlab
6
References
https://gitlab.com/gitlab-org/gitlab/-/issues/247523
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/247523
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
5.9 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-02T15:15:12.833Z
4 years agoLast modified
2024-11-21T04:49:41.770Z
1 year ago