Impact
The vulnerability arises from an improper authorization check in GitLab’s merge request collaboration settings. An authenticated user with a developer role that has been removed from a project could still commit changes to that project’s repository. This allows an attacker who has previously been granted developer permissions to introduce unauthorized code or configuration changes after the user’s membership has been revoked, potentially compromising the integrity of the codebase.
Affected Systems
Affected versions include GitLab Community Edition and Enterprise Edition from 10.6 up through versions prior to 19.0.5, from 19.1.0 to 19.1.2, and from 19.2.0 to 19.2.0. All patch releases 19.0.5, 19.1.3, 19.2.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity impact, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability requires an attacker to be an authenticated developer who can be removed yet still retain pending merge request collaboration permissions; thus, the attack vector is internal. Because it is not listed in the CISA KEV catalog, no known exploit code is publicly available, but the risk remains if mitigations are not applied.
OpenCVE Enrichment