A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 13.12.0 | 13.12.6 |
| gitlab / gitlab | 14.0.0 | 14.0.2 |