Impact
GitLab Enterprise Edition versions prior to 18.11.6, 19.0.3, and 19.1.1 have a missing authorization check that can allow an authenticated user with limited permissions to view project information. This flaw is a missing authorization weakness (CWE-862) and can lead to confidential project data being accessed without proper privilege.
Affected Systems
GitLab product, Enterprise Edition. Affected releases include any version from 18.6 up to, but not including, 18.11.6; from 19.0 up to, but not including, 19.0.3; and from 19.1 up to, but not including, 19.1.1. All other recent GitLab EE versions are not impacted.
Risk and Exploitability
The CVSS base score of 3.1 indicates low severity; the exploit probability EPSS is not available and the vulnerability is not listed in CISA KEV. An attacker must be an authenticated user with limited permissions; exploitation requires exploiting the insufficient authorization logic. While the risk level is modest, the potential for exposing project data mandates remediation.
OpenCVE Enrichment