Related Vulnerabilities: CVE-2021-39930  

Missing authorization in GitLab EE versions starting from 12.4 before 14.3.6, starting from 14.4.0 before 14.4.4, and starting from 14.5.0 before 14.5.2 allowed an attacker to access a user's custom project and group templates.

Severity Medium

Remote Yes

Type Information disclosure

Description

Missing authorization in GitLab EE versions starting from 12.4 before 14.3.6, starting from 14.4.0 before 14.4.4, and starting from 14.5.0 before 14.5.2 allowed an attacker to access a user's custom project and group templates.

AVG-2604 gitlab 14.5.0-1 Medium Not affected

https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/