An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/408137 Broken Link Vendor Advisory
https://hackerone.com/reports/1944500 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2023-07-13T02:00:02.797Z

Updated: 2023-07-13T02:00:02.797Z

Reserved: 2023-04-19T22:23:17.062Z


Link: CVE-2023-2190

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-13T02:15:09.203

Modified: 2023-07-20T20:39:14.363


Link: CVE-2023-2190

JSON object: View

cve-icon Redhat Information

No data.

CWE