Multiple vulnerabilities have been reported in GitLab CE/EE that could allow a remote attacker to trigger cross-site scripting, disclose sensitive information, bypass security restriction and cause denial of service (DoS) condition on the targeted system.
Target Audience:
Organizations and individuals operating self-managed GitLab CE/EE instances.
Risk Assessment:
Risk of unauthorized access, information disclosure, improper access control, input validation abuse, service unavailability.
Impact Assessment:
Potential for unauthorized access to sensitive data, disruption of services.
The information provided herein is on "as is" basis, without warranty of any kind.