Description
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
Affected products
- gitlab / GitLab Community and Enterprise Editions8.10.6 - 10.1.5 Fixed in 10.1.6 – 8.10.6 - 10.1.5 Fixed in 10.1.6
- gitlab / GitLab Community and Enterprise Editions10.2.0 - 10.2.5 Fixed in 10.2.6 – 10.2.0 - 10.2.5 Fixed in 10.2.6
- gitlab / GitLab Community and Enterprise Editions10.3.0 - 10.3.3 Fixed in 10.3.4 – 10.3.0 - 10.3.3 Fixed in 10.3.4