GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gitlab | Gitlab | * | 12.8.1 (including) |
| Gitlab | Ubuntu | esm-apps/xenial | * |
| Gitlab | Ubuntu | upstream | * |
| Gitlab | Ubuntu | xenial | * |