GitLab repository branch prefix can be updated by any user
Package
Tuleap Community Edition
(tuleap)
Affected versions
>= 12.9.99.228 && < 14.0.99.24
Patched versions
14.0.99.24
Tuleap Enterprise Edition
(tuleap)
>= 14.0 && < 14.0-3
>= 12.10 && < 13.12-6
14.0-3
13.12-6
Authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration.
Impact
Authenticated users can change the branch prefix of any of the GitLab repository integration they can see vie the REST endpoint
PATCH /gitlab_repositories/{id}
. This action should be restricted to Git administrators.Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References