An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
{
"versions": [
{
"introduced": "10.7.0"
},
{
"fixed": "12.7.9"
},
{
"introduced": "12.8.0"
},
{
"fixed": "12.8.9"
},
{
"introduced": "12.8.0"
},
{
"fixed": "12.8.9"
},
{
"introduced": "12.9.0"
},
{
"fixed": "12.9.3"
},
{
"introduced": "12.9.0"
},
{
"fixed": "12.9.3"
}
]
}