An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owners Sentry instance projects.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 11.8 (including) | 16.2.8 (excluding) |
Gitlab | Gitlab | 16.3.0 (including) | 16.3.5 (excluding) |
Gitlab | Gitlab | 16.4.0 (including) | 16.4.0 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | upstream | * |