Description
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
Problem types
CWE-862: Missing Authorization
Product status
17.7 (semver) before 17.9.7
17.10 (semver) before 17.10.5
17.11 (semver) before 17.11.1
Credits
Thanks [mateuszek](https://hackerone.com/mateuszek) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/508046 (GitLab Issue #508046)
hackerone.com/reports/2862754 (HackerOne Bug Bounty Report #2862754)