Due to an insecure direct object reference vulnerability...
Moderate severity
Unreviewed
Published
May 12, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 11, 2022
Published to the GitHub Advisory Database
May 12, 2022
Last updated
Feb 1, 2023
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.
References