Impact
GitLab Enterprise Edition includes a missing authorization check on a project update endpoint. This flaw allows an authenticated user to change project settings that should only be accessible to higher‑privileged roles, enabling the user to persist unauthorized configuration changes.
Affected Systems
GitLab Enterprise Edition versions 19.1 before 19.1.4 and 19.2 before 19.2.2. All newer releases are secure.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. EPSS data is not available, so exploitation likelihood cannot be quantified. The issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated account; once logged in, a user can modify settings that should be protected, leading to an unauthorized configuration state.
OpenCVE Enrichment