An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 13.9.0 | 13.9.2 |
| gitlab / gitlab | 13.8.0 | 13.8.5 |
| gitlab / gitlab | 9.4.0 | 13.7.8 |