An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.
{
"cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "11.3.0"
},
{
"fixed": "12.5.9"
},
{
"introduced": "12.6.0"
},
{
"fixed": "12.6.6"
},
{
"introduced": "12.7.2"
},
{
"fixed": "12.7.4"
}
]
}