Description
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.
Problem types
CWE-288: Authentication Bypass Using an Alternate Path or Channel
Product status
17.11 (semver) before 18.7.5
18.8 (semver) before 18.8.5
18.9 (semver) before 18.9.1
Credits
Thanks [modhanami](https://hackerone.com/modhanami) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/issues/588385 (GitLab Issue #588385)
hackerone.com/reports/3533088 (HackerOne Bug Bounty Report #3533088)
about.gitlab.com/...25/patch-release-gitlab-18-9-1-released/