Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.
Problem types
CWE-862: Missing Authorization
Product status
18.7 (semver) before 18.10.7
18.11 (semver) before 18.11.4
19.0 (semver) before 19.0.1
Credits
Thanks [rogerace](https://hackerone.com/rogerace) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/work_items/595423
hackerone.com/reports/3626303 (HackerOne Bug Bounty Report #3626303)
about.gitlab.com/...27/patch-release-gitlab-19-0-1-released/