An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
{
"extracted_events": [
{
"introduced": "10.7.0"
},
{
"fixed": "12.7.9"
},
{
"introduced": "10.7.9"
},
{
"introduced": "12.8.0"
},
{
"fixed": "12.8.9"
},
{
"introduced": "12.9.0"
},
{
"fixed": "12.9.3"
}
],
"source": "CPE_RANGE",
"cpe": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*"
]
}