Related Vulnerabilities: CVE-2021-39875  

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

Severity Medium

Remote Yes

Type Information disclosure

Description

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

AVG-2431 gitlab 14.3.0-1 14.3.1-1 High Fixed

https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#pending-invitations-of-public-groups-and-public-projects-are-visible-to-any-user