CVE-2022-1963
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab reveals if a user has enabled two-factor authentication on their account in the HTML source, to unauthenticated users.
Summary dbcve.org
GitLab CE/EE exposes whether a user has enabled two-factor authentication in the HTML source to unauthenticated (non-logged-in) visitors. This information disclosure occurs through the user interface or API responses that include 2FA status in page HTML, allowing attackers to enumerate which accounts have enhanced security.
Mitigation
Upgrade GitLab to versions 14.10.5, 15.0.4, 15.1.1 or later. Self-hosted deployments should apply the patch version corresponding to their current major release.