An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
2023-09-01T11:15:42.457
2024-11-21T08:18:23.267
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.2.5 | Yes |
Application | gitlab | gitlab | < 16.2.5 | Yes |
Application | gitlab | gitlab | 16.3.0 | Yes |
Application | gitlab | gitlab | 16.3.0 | Yes |