Information disclosure in Gitlab Community Edition - CVE-2019-15591
Published: December 18, 2019 / Updated: July 17, 2020
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.