#VU21188 Improper access control in GitLab Enterprise Edition - CVE-2019-16170
Published: September 18, 2019
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions in the project creation using custom group templates. A remote authenticated attacker can send a specially crafted request, clone a project to which he has partial visibility and see the restricted information on the target system.