Total vulnerabilities in the database
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
Software | From | Fixed in |
---|---|---|
gitlab / gitlab | 14.2 | 14.2.5 |
gitlab / gitlab | 14.3.0 | 14.3.1 |
gitlab / gitlab | 11.3 | 14.1.7 |
gitlab / gitlab | 11.3.0 | 14.1.7 |