#VU28328 Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition
Published: May 28, 2020
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application may expose presence of files on the system. A remote non-authenticated attacker can send a specially crafted request and confirm the existence of files hosted on object storage services, without disclosing their contents.