Correction updates for the collaborative development platform have been released — GitLab 15.11.2, 15.10.6, and 15.9.7, which address a critical vulnerability (CVE-2023-2478) that allows any authenticated user to attach their own runner handler (an application for running tasks during the code build in the continuous integration system) to any project on the same server through manipulations with the GraphQL API. Details of the exploitation have not yet been provided. Information about the vulnerability has been submitted to GitLab under the active HackerOne bug bounty program.
Source: opennet.ru