An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners
{
"versions": [
{
"introduced": "9.4.0"
},
{
"fixed": "13.7.8"
},
{
"introduced": "9.4.0"
},
{
"fixed": "13.7.8"
},
{
"introduced": "13.8.0"
},
{
"fixed": "13.8.5"
},
{
"introduced": "13.8.0"
},
{
"fixed": "13.8.5"
},
{
"introduced": "13.9.0"
},
{
"fixed": "13.9.2"
},
{
"introduced": "13.9.0"
},
{
"fixed": "13.9.2"
}
]
}