#VU28327 Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition

 

#VU28327 Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition

Published: May 28, 2020


Vulnerability identifier: #VU28327
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Gitlab Community Edition
GitLab Enterprise Edition
Software vendor:
GitLab, Inc

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the Kubernetes cluster token is visible to other group maintainers.


Remediation

Install updates from vendor's website.

External links