A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 7.10.0 (including) | 13.10.5 (excluding) |
Gitlab | Gitlab | 13.11.0 (including) | 13.11.5 (excluding) |
Gitlab | Gitlab | 13.12.0 (including) | 13.12.2 (excluding) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | upstream | * |