An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 12.9.0 (including) | 15.4.6 (excluding) |
Gitlab | Gitlab | 15.5.0 (including) | 15.5.5 (excluding) |
Gitlab | Gitlab | 15.6.0 (including) | 15.6.0 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | trusty | * |
Gitlab | Ubuntu | xenial | * |