Partial PII leakage due to public set gitlab

Disclosed: 2019-12-02 19:06:43 By alyssa_herrera To deptofdefense
Medium
Vulnerability Details
**Summary:** ████████ allows you to explore the repos, snippets,etc. On the snippets we find a name+icon and some code information. This shouldn't publicly exposed as an attacker may use it to perform further attacks **Description:** A configuration issue allows code and the name+icon of a user on the gitlab instance to leaked publicly. ## Impact A tiny bit of PII leakage, mainly name+ personal picture. Along with a bit of code leakage ## Step-by-step Reproduction Instructions https://█████/snippets/72 https://███/explore/snippets ## Product, Version, and Configuration (If applicable) Gitlab ## Suggested Mitigation/Remediation Actions Make private ## Impact Recovery of partial code and username+picture
Actions
View on HackerOne
Report Stats
  • Report ID: 375091
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report