Impact
GitLab Enterprise Edition contains an improper authorization check on a group settings page. The bug can allow an authenticated user to view configuration settings that are intended to be restricted, leading to possible exposure of sensitive configuration data. This flaw is classified as an authorization bypass (CWE‑862).
Affected Systems
All GitLab EE instances from version 17.7 through 18.x, 19.0.5, 19.1.3, and 19.2.1 are vulnerable. The vendor recommendation is to upgrade to version 19.0.6, 19.1.4, 19.2.2, or any later release. The affected product is GitLab EE (Enterprise Edition).
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, and the EPSS score is currently unavailable, meaning no quantified likelihood of exploitation is provided. Because the flaw requires an authenticated user and is not listed in CISA’s KEV catalog, the exploitation probability appears to be low. The most likely attack scenario involves a legitimate user with access to the group settings page exploiting the missing authorization check.
OpenCVE Enrichment