Impact
GitLab contains a flaw that lets an authenticated user with Guest permissions read issue data from projects that are out of the user’s authority, thereby leaking potentially sensitive information. The weakness is an authorization control failure classified under CWE‑639. The vulnerability does not alter code execution or system integrity but exposes confidential issue details to unintended viewers.
Affected Systems
The flaw affects GitLab Community Edition and Enterprise Edition builds from version 15.1 up through all releases prior to 18.9.7, 18.10.6, and 18.11.3. Any project hosted on these versions where a user has a Guest role is susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of widespread exploitation. Exploitation requires an authenticated session with Guest privileges and the action of request‑ing issue data, meaning that standard authentication is a prerequisite. The attack vector is therefore authenticated local or remote access within the GitLab instance, without requiring additional administrative privileges.
OpenCVE Enrichment