An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
{ "versions": [ { "introduced": "14.6" }, { "fixed": "14.6.2" } ] }
{ "versions": [ { "introduced": "14.5" }, { "fixed": "14.5.3" } ] }