Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-22167
Published: January 8, 2021 / Updated: January 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. Incorrect headers within a specific project page allows attacker to have temporary read access to a public repository with project features restricted to only members.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2021-22167
GitLab Enterprise Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2