Impact
The vulnerability resides in GitLab Enterprise Edition’s handling of custom role assignments. When a user has a pending membership, GitLab may incorrectly grant that user the permissions associated with a custom role, allowing an attacker who controls or abuses such a pending membership to acquire unauthorized privileges, which is a classic CWE‑266 weakness.
Affected Systems
The issue affects GitLab Enterprise Edition across a broad range of releases: all versions from 15.6 up to but excluding 19.0.6, from 19.1 up to excluding 19.1.4, and from 19.2 up to excluding 19.2.2. Updating to any version 19.0.6, 19.1.4, 19.2.2 or later resolves the problem.
Risk and Exploitability
The CVSS score is 3.3, indicating low overall severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack surface requires an account with a pending association to leverage the custom role; it is therefore limited to users who already have a pending membership within the system. While the risk is low, the potential for unauthorized privilege escalation warrants patching. The vendor recommends upgrading to the stated patched releases to eliminate the flaw.
OpenCVE Enrichment