Impact
GitLab exposes a flaw that, under certain conditions, allows an authenticated user to create a new repository where the files shown in the web interface differ from the files retrieved when the repository is downloaded. This mismatch occurs because the system does not resolve Git reference names correctly during repository uploads. The result is a situation where the displayed content can mislead users, potentially enabling malicious actors to present altered or misleading content to those who rely on the web view.
Affected Systems
GitLab Community Edition and Enterprise Edition across all releases from version 16.5 up to but not including 18.11.7, from 19.0 up to but not including 19.0.4, and from 19.1 up to but not including 19.1.2. The affected offerings include both source and packaged distributions as noted by the vendor.
Risk and Exploitability
The CVSS score of 3.5 classifies the vulnerability as low severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV, which suggests no known active exploitation. The likely attack vector requires an authenticated user with permission to create new repositories; no remote code execution or network-based attack is possible. Overall, the risk is modest and limited to confusing or misleading users within the compromised environment.
OpenCVE Enrichment