Multiple vulnerabilities have been reported in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow an attacker to bypass authorization controls, execute arbitrary client-side code, read arbitrary local files, add unauthorized emails, or cause a Denial of Service (DoS) on the targeted system.
Target Audience:
Organizations and individuals using affected GitLab Community Edition (CE) and Enterprise Edition (EE) instances.
Risk Assessment:
Potential risk of unauthorized access, information disclosure, privilege misuse and denial of service.
Impact Assessment:
Risk of account compromise, unauthorized information disclosure and service disruption.
The information provided herein is on "as is" basis, without warranty of any kind.