Impact
GitLab Community Edition and Enterprise Edition releases prior to 19.0.5, 19.1.3, and 19.2.1 allow an authenticated user with guest role permissions to access test report contents they are not authorized to view, which can lead to the disclosure of sensitive data. The flaw is an improper authorization check identified as CWE-862.
Affected Systems
Vulnerable products include GitLab Community Edition and Enterprise Edition. All releases from 18.4 up to, but not including, 19.0.5, 19.1.3, and 19.2.1 are affected. Users should verify the exact minor release of their instance to determine risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation. This vulnerability is not listed in CISA KEV. Attackers would need to authenticate to the system and hold a guest role; the flaw is triggered by the presence of a guest user and does not require elevated privileges or remote code execution.
OpenCVE Enrichment