An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.
{
"versions": [
{
"introduced": "11.9.0"
},
{
"fixed": "11.9.10"
},
{
"introduced": "11.9.0"
},
{
"fixed": "11.9.10"
},
{
"introduced": "11.10.0"
},
{
"fixed": "11.10.2"
},
{
"introduced": "11.10.0"
},
{
"fixed": "11.10.2"
}
]
}