Incorrect Authorization check affecting all versions of...
High severity
Unreviewed
Published
Jan 12, 2023
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 12, 2023
Published to the GitHub Advisory Database
Jan 12, 2023
Last updated
Feb 3, 2023
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
References