Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.
Problem types
CWE-862: Missing Authorization
Product status
13.7 (semver) before 18.2.8
18.3 (semver) before 18.3.4
18.4 (semver) before 18.4.2
Credits
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
References
about.gitlab.com/...08/patch-release-gitlab-18-4-2-released/
gitlab.com/gitlab-org/gitlab/-/issues/567301 (GitLab Issue #567301)
hackerone.com/reports/3319800 (HackerOne Bug Bounty Report #3319800)