Description
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.
Problem types
CWE-862: Missing Authorization
Product status
15.2 (semver) before 16.1.5
16.2 (semver) before 16.2.5
16.3 (semver) before 16.3.1
Credits
Thanks [ali_shehab](https://hackerone.com/ali_shehab) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/398587 (GitLab Issue #398587)
hackerone.com/reports/1911908 (HackerOne Bug Bounty Report #1911908)
gitlab.com/gitlab-org/gitlab/-/issues/398587 (GitLab Issue #398587)
hackerone.com/reports/1911908 (HackerOne Bug Bounty Report #1911908)