What the vulnerability does

01Description

An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

Key dates

02Disclosure timeline

January 28, 2020 CVE published
August 5, 2024 Record updated