Impact
This vulnerability in GitLab Enterprise Edition allows an authenticated user to modify group-level settings beyond the permissions intended by the system, because of improper authorization controls (CWE-863).
Affected Systems
All GitLab Enterprise Edition releases from version 16.10 up to, but not including, 18.11.7, as well as 19.0.0 through 19.0.3 and 19.1.0 through 19.1.1. The product is GitLab EE.
Risk and Exploitability
The CVSS score of 2.7 classifies this weakness as low severity, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated within the GitLab instance to exploit the flaw, typically by submitting requests that change group settings that are normally restricted to group owners or administrators.
OpenCVE Enrichment