Total vulnerabilities in the database
In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.
Software | From | Fixed in |
---|---|---|
gitlab / gitlab | 10.5.0 | 12.3.8.x |
gitlab / gitlab | 12.4.0 | 12.4.5.x |
gitlab / gitlab | 12.5.0 | 12.5.3.x |