An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
{
"versions": [
{
"introduced": "9.5.0"
},
{
"fixed": "12.9.8"
},
{
"introduced": "9.5.0"
},
{
"fixed": "12.9.8"
},
{
"introduced": "12.10.0"
},
{
"fixed": "12.10.7"
},
{
"introduced": "12.10.0"
},
{
"fixed": "12.10.7"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "13.0.0"
}
]
}