"value":"An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere",
"value":"Upgrade to versions 17.1.7, 17.2.5, 17.3.2 or above."
}
],
"credits":[
{
"lang":"en",
"value":"Thanks [ashish_r_padelkar](https://hackerone.com/ashish_r_padelkar) for reporting this vulnerability through our HackerOne bug bounty program"