Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2021-10-05T13:39:17

Updated: 2021-10-05T13:39:17

Reserved: 2021-08-23T00:00:00


Link: CVE-2021-39886

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-05T14:15:07.933

Modified: 2021-10-09T03:30:27.597


Link: CVE-2021-39886

JSON object: View

cve-icon Redhat Information

No data.

CWE