Impact
The vulnerability arises from improper handling of job dependencies in GitLab Enterprise Edition’s Pipeline Execution Policy enforcement. An authenticated user with developer permissions can introduce untrusted data together with trusted data, altering the execution environment and potentially bypassing policy checks. Classified as CWE‑349, this flaw reveals inadequate protection of trusted data sources, which could compromise the integrity or availability of pipeline operations.
Affected Systems
GitLab Enterprise Edition is impacted for all releases from 19.1 up to, but not including, 19.1.7; from 19.2 up to, but not including, 19.2.5; and from 19.3 up to, but not including, 19.3.1. These versions span on‑premises installations as well as GitLab.com hosting, making the issue relevant to a broad range of enterprise deployments.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability carries moderate severity in isolation, and it is not listed in CISA KEV, lowering immediate public visibility. Exploitation requires an authenticated developer‑role account that can adjust pipeline job dependencies, indicating a likely internal threat scenario. An attacker could inject untrusted data to modify the execution context, undermining policy enforcement or allowing unauthorized job behavior.
OpenCVE Enrichment