CVE

CVE-2021-39876

CVE-2021-39876

In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

Source: CVE-2021-39876

Exit mobile version