An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 10.0.0 | 10.8.7.x |
| gitlab / gitlab | 9.0.0 | 9.3.7.x |
| gitlab / gitlab | 11.10.0 | 11.10.2 |
| gitlab / gitlab | 11.9.0 | 11.9.10 |
| gitlab / gitlab | 11.0.0 | 11.8.9 |
| gitlab / gitlab | 11.10.0 | 11.10.2.x |
| gitlab / gitlab | 8.1.0 | 8.17.8.x |