Impact
GitLab Enterprise Edition versions preceding 19.1.3 and 19.2.1 contain a flaw in token generation that can allow an authenticated user to obtain a security token with privileges beyond those intended by administrator‑configured tool governance policies. This improper authorization check, classified as CWE‑1270, could enable the user to perform privileged actions or access sensitive data that should have been restricted.
Affected Systems
The vulnerability affects all installations of GitLab Enterprise Edition running version 19.1 before 19.1.3 and version 19.2 before 19.2.1. Any user with authentication credentials on such a system is potentially at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates low to medium severity, and the EPSS score is below 1%, suggesting that exploitation attempts are unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session and the ability to trigger token generation under specific conditions, making the attack vector limited to users already possessing valid credentials. Overall, the risk remains low to moderate unless an attacker already has user credentials.
OpenCVE Enrichment