Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
{
"versions": [
{
"introduced": "13.1.0"
},
{
"fixed": "13.12.9"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.12.9"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.7"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.7"
},
{
"introduced": "14.1.0"
},
{
"fixed": "14.1.2"
},
{
"introduced": "14.1.0"
},
{
"fixed": "14.1.2"
}
]
}