Impact
The vulnerability is an improper authorization check in GitLab Enterprise Edition that allows an authenticated user with the Security Manager role to trigger arbitrary CI/CD jobs and retrieve protected group variables. This flaw is formally classified as CWE‑862. The potential impact is that a user with legitimate credentials could execute arbitrary code on the CI runner and exfiltrate sensitive configuration data, effectively bypassing intended access controls. The flaw could also be used to compromise the integrity of build pipelines.
Affected Systems
Affected products are GitLab Enterprise Edition for all releases from 18.11 up to, but not including, 19.1.8, 19.2.6, and 19.3.2. Users running any of these product versions are susceptible until they apply the official patch. The CVE references indicate that the issue has been addressed in the 19.1.8, 19.2.6, and 19.3.2 releases and later.
Risk and Exploitability
The CVSS base score is 4.3, reflecting moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild. No entries exist in the CISA KEV catalog, and the exploit requires a valid authenticated session with a specific role; no public or remote exploitation method is known. Despite the low risk metrics, the ability to run arbitrary jobs remains a significant risk within a compromised internal environment; therefore the recommended response is to patch.
OpenCVE Enrichment