All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
{
"versions": [
{
"introduced": "9.5.0"
},
{
"fixed": "13.10.5"
},
{
"introduced": "9.5.0"
},
{
"fixed": "13.10.5"
},
{
"introduced": "13.11.0"
},
{
"fixed": "13.11.5"
},
{
"introduced": "13.11.0"
},
{
"fixed": "13.11.5"
},
{
"introduced": "13.12.0"
},
{
"fixed": "13.12.2"
},
{
"introduced": "13.12.0"
},
{
"fixed": "13.12.2"
}
]
}