Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 14.4.0 | 14.4.4 |
| gitlab / gitlab | 14.5.0 | 14.5.2 |
| gitlab / gitlab | 12.4.0 | 14.3.6 |