CVE-2021-22188
Description
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
Summary dbcve.org
GitLab versions 13.0 and later contained an information disclosure vulnerability where confidential issue titles were exposed through branch logs to unauthorized users. The access control logic for issue titles did not properly enforce confidentiality when displaying information via the branch logs feature, allowing any user with repository access to view sensitive issue titles they should not have access to.
Mitigation
Update GitLab to the patched version (14.x or later per vendor advisories). If immediate patching is not feasible, restrict user access to repositories and review branch log visibility settings to limit exposure of sensitive metadata.