Description
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
Problem types
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
Any version before 17.10.8
17.11 (semver) before 17.11.4
18.0 (semver) before 18.0.2
Credits
Thanks [hdtran](https://hackerone.com/hdtran) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/497748 (GitLab Issue #497748)
hackerone.com/reports/2683469 (HackerOne Bug Bounty Report #2683469)