Impact
GitLab Enterprise Edition versions prior to the patched releases exposed a flaw in authorization checks, corresponding to CWE-266: Improper Authentication and CWE-522: Sensitive Data Exposure. This flaw could with maintainer role permissions to read other users’ stored credentials when certain conditions were met. The weakness centers on improper authorization controls, allowing credential disclosure to a privileged but non-administrator user.
Affected Systems
GitLab EE is affected, specifically all releases from 9.5 up to but not including 18.11.7, all 19.0 releases up to but not including 19.0.4, and all 19.1 releases up to but not including 19.1.2.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity known at this time. Exploitation requires the attacker to be a legitimate GitLab user with maintainer role privileges; consequently the attack surface is restricted a wide range of users.
OpenCVE Enrichment