What the vulnerability does

01Description

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

Key dates

02Disclosure timeline

December 18, 2019 CVE published
August 5, 2024 Record updated