CVE-2022-0172
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of issues, merge requests and milestones.
Summary dbcve.org
GitLab CE/EE versions 12.3 and later contained a vulnerability where IP restrictions intended for public projects could be bypassed through the GraphQL API. This allowed unauthenticated attackers to read the titles of issues, merge requests, and milestones that should have been restricted based on IP whitelisting rules.
Mitigation
Upgrade GitLab to a patched version (refer to GitLab's official security release for version-specific patches). After upgrading, verify that IP restriction policies are properly enforced for GraphQL API endpoints.