An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners
An authorization issue in GitLab CE/EE version 94 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners The issue is fixed in GitLab versions 1392, 1385 and 1378 ...