Impact
The vulnerability is an authentication bypass using an alternate path that allows a user with project Maintainer permissions to access the terminal of a protected environment they are not authorized to use. This unauthorized access can enable the attacker to execute commands within the environment, potentially compromising confidentiality and integrity of the affected system. The weakness is a failure of proper authorization checks, classified as CWE-288.
Affected Systems
The affected product is GitLab Enterprise Edition as distributed by GitLab, with all releases from 11.3 up to but excluding 19.1.7, from 19.2 up to but excluding 19.2.5, and from 19.3 up to but excluding 19.3.1. These versions are legacy builds that remain in many organizations' environments.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with Maintainer privileges and knowledge of the target environment; no special privileges beyond project authorization are needed. Because the attacker can gain terminal access, the risk includes remote code execution and privilege escalation within the protected environment.
OpenCVE Enrichment