An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-22186.json"