Total vulnerabilities in the database
An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: