An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2022-01-18T16:51:53

Updated: 2024-08-02T23:18:41.998Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-0172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-01-18T17:15:10.187

Modified: 2023-08-08T14:21:49.707

Link: CVE-2022-0172

cve-icon Redhat

No data.