Impact
GitLab Community and Enterprise Editions use an environment scope pattern matcher that, due to improper input validation, can allow an authenticated user to view CI/CD variables that are scoped to a different environment. The flaw permits the attacker to read secrets normally restricted to a specific environment, potentially exposing credentials, tokens, or other confidential data. This issue corresponds to the CWE‑863 "Improper Authorization" weakness.
Affected Systems
Affected systems include all GitLab Community Edition and Enterprise Edition releases starting with version 15.7 and up through the latest releases; unpatched versions less than 19.1.8, less than 19.2.6, or less than 19.3.2 are vulnerable. Users running those versions are susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 7.7 classifies this flaw as high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that active exploitation is not currently known. The likely attack vector requires a valid authenticated account to supply a crafted environment scope pattern. Once authenticated, the attacker can read variables that should belong to another environment, giving them the ability to compromise downstream deployments or expose secrets to unprivileged users.
OpenCVE Enrichment