Improper access control in GitLab Enterprise Edition - CVE-2017-11437
Published: June 22, 2019
GitLab Enterprise Edition
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when reading repositories belonging to other users. A remote authenticated user with the ability to create a project to use the mirroring feature can read repositories that belong to other users.