Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.
Problem types
CWE-1289: Improper Validation of Unsafe Equivalence in Input
Product status
18.8 (semver) before 18.8.4
Credits
Thanks [u3mur4](https://hackerone.com/u3mur4) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/586483 (GitLab Issue #586483)
hackerone.com/reports/3502519 (HackerOne Bug Bounty Report #3502519)
about.gitlab.com/...10/patch-release-gitlab-18-8-4-released/