Related Vulnerabilities: CVE-2021-22200  

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7.

Severity Medium

Remote Yes

Type Information disclosure

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7.

AVG-1770 gitlab 13.9.4-1 13.10.1-1 Critical Testing

https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/#access-data-of-an-internal-project-through-a-public-project-fork-as-an-anonymous-user
https://gitlab.com/gitlab-org/gitlab/-/issues/247523