Description
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
Problem types
CWE-312: Cleartext Storage of Sensitive Information
Product status
16.2 (semver) before 16.2.5
16.3 (semver) before 16.3.1
Credits
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/419675 (GitLab Issue #419675)
hackerone.com/reports/2079154 (HackerOne Bug Bounty Report #2079154)
gitlab.com/gitlab-org/gitlab/-/issues/419675 (GitLab Issue #419675)
hackerone.com/reports/2079154 (HackerOne Bug Bounty Report #2079154)