Impact
The vulnerability stems from insufficient validation of job submissions for service accounts in Jacamar CI versions prior to 0.30.0. Authenticated CI users can inject arbitrary service account names into job configurations. This lack of validation effectively allows an attacker to bypass authentication controls and create or impersonate service accounts that are normally granted higher privileges within the CI environment. The weakness is classified as improper enforcement of authentication, corresponding to CWE‑290.
Affected Systems
Jacamar CI deployments running any version earlier than 0.30.0 are affected when they run against GitLab Server versions 13.11 or newer, or when used with GitLab Server 13.10 with the allow_projects_to_create_service_accounts flag enabled. Later releases of either Jacamar CI or GitLab Server that do not expose the vulnerable configuration path are not affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability with significant impact on confidentiality and integrity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, but the required attacker credential is a legitimate CI user, which exists in many enterprises. The likely attack vector therefore involves an authenticated CI user who can trigger a job and supply arbitrary service account names, enabling unauthorized creation of privileged accounts. Security teams should treat this as a high‑risk vulnerability requiring urgent remediation.
OpenCVE Enrichment