Very proud of our security team for the responsive communication and ensuring the issue is made public https://gitlab.com/gitlab-org/gitlab-ce/issues/54189#note_12...
Appreciate the transparency. Was there any evidence of exploitation found? At least the researcher should have been identified as true positive compromising their own account to ensure post mortem investigation was correct and no other customers were impacted/exploited by a real adversary.