Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition - #VU28328
Published: May 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application may expose presence of files on the system. A remote non-authenticated attacker can send a specially crafted request and confirm the existence of files hosted on object storage services, without disclosing their contents.
Affected software
GitLab Enterprise Edition
Remediation
GitLab Enterprise Edition - addressed in versions 12.10.7, 13.0.1