An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 11.6.0 (including) | 13.9.7 (excluding) |
Gitlab | Gitlab | 13.10.0 (including) | 13.10.4 (excluding) |
Gitlab | Gitlab | 13.11.0 (including) | 13.11.2 (excluding) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | xenial | * |