GHSA-q9c5-pp7m-fm2g: Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Two endpoints serving in-house iOS application packages and manifests in Fleet’s enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by guessing sequential title identifiers.
References
Code Behaviors & Features
Detect and mitigate GHSA-q9c5-pp7m-fm2g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →