Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 10.3.0 | 10.3.3.x |
| gitlab / gitlab | 10.0.0 | 10.1.5.x |
| gitlab / gitlab | 10.2.0 | 10.2.5.x |
| gitlab / gitlab | 9.1.0 | 9.5.10.x |