Impact
GitLab allows an authenticated user with maintainer permissions to send requests to internal network resources through mirror synchronization because the system does not properly validate URLs. This flaw enables the attacker to access internal services, potentially exposing sensitive data or creating a foothold for further attacks. The weakness is a functional flaw in input validation, identified as CWE-350.
Affected Systems
The vulnerability affects GitLab Community and Enterprise editions across a wide range of releases: all versions from 8.3 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1. The affected product is GitLab, and it is reported by the CNA as impacting the vendor’s main repository product.
Risk and Exploitability
The CVSS score is not listed, and EPSS is unavailable, indicating that no public exploitation data are currently reported. However, the vulnerability requires an authenticated maintainer, meaning that an insider or compromised account with such privileges could exploit it. Because the flaw permits traffic to internal services, the risk is high for systems with sensitive internal resources. Although the flaw is not recorded in the CISA KEV catalog, organizations using unpatched GitLab editions should treat it as a serious exposure.
OpenCVE Enrichment