gitlab-org/gitlab-workhorse

gitlab-org/gitlab-workhorse

Releases244
Frequency1 week 1 day
Last Release
Stars116
Handles slow HTTP requests for GitLab

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM4 MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

6.5 MEDIUM4 MEDIUM

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.