Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
Problem types
CWE-840: Business Logic Errors
Product status
18.4 (semver) before 18.4.3
18.5 (semver) before 18.5.1
Credits
Thanks [rhidayahh](https://hackerone.com/rhidayahh) for reporting this vulnerability through our HackerOne bug bounty program
References
about.gitlab.com/...22/patch-release-gitlab-18-5-1-released/
gitlab.com/gitlab-org/gitlab/-/issues/551267 (GitLab Issue #551267)
hackerone.com/reports/3209641 (HackerOne Bug Bounty Report #3209641)