Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.
{
"cpe": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
],
"extracted_events": [
{
"introduced": "10.7.0"
},
{
"fixed": "14.3.6"
},
{
"introduced": "14.4.0"
},
{
"fixed": "14.4.4"
},
{
"introduced": "14.5.0"
},
{
"fixed": "14.5.2"
}
],
"source": "CPE_RANGE"
}