An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the super_sidebar_logged_out
feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 16.0.0 (including) | 16.3.6 (excluding) |
Gitlab | Gitlab | 16.4.0 (including) | 16.4.2 (excluding) |
Gitlab | Gitlab | 16.5.0 (including) | 16.5.0 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |