Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.
{
"versions": [
{
"introduced": "13.1.0"
},
{
"fixed": "13.12.9"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.12.9"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.7"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.7"
},
{
"introduced": "14.1.0"
},
{
"fixed": "14.1.2"
},
{
"introduced": "14.1.0"
},
{
"fixed": "14.1.2"
}
]
}