Impact
An authenticated user with access to GitLab Enterprise Edition can trigger a GraphQL query that bypasses the normal authorization logic, allowing the user to read policy configuration files of a namespace to which the user is not granted permission. This flaw is a classic Authorization Bypass (CWE‑863) that permits data exposure without affecting code execution or availability.
Affected Systems
The vulnerability affects all GitLab Enterprise Edition releases prior to version 19.1.4 and all releases prior to 19.2.2. Only the newer releases address the issue; older releases continue to expose policy data to unauthorized users.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate potential impact. Because the EPSS score is not available, the likelihood of exploitation cannot be quantified, but the vulnerability is not listed in CISA’s KEV catalog. Attackers would need an authenticated account on the affected instance; the flaw does not provide privilege escalation or remote code execution. Nonetheless, any compromised or malicious legitimate account could gain insight into organizational policies, potentially aiding broader attacks. The risk level is therefore moderate, warranting remediation as soon as possible.
OpenCVE Enrichment