Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
The product does not properly “clean up” and remove temporary or supporting resources after they have been used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 11.2.0 (including) | 13.2.10 (excluding) |
Gitlab | Gitlab | 13.3.0 (including) | 13.3.7 (excluding) |
Gitlab | Gitlab | 13.4.0 (including) | 13.4.2 (excluding) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | xenial | * |