Impact
This vulnerability permits an authenticated user to trigger Duo AI workflow runners on behalf of another user due to faulty user identity resolution when initiating the workflow. The result is that the workflow executes with the target user's privileges, effectively allowing the attacker to execute arbitrary actions under that user’s identity.
Affected Systems
GitLab Enterprise Edition is affected. Versions from 18.8 prior to 18.10.7, from 18.11 prior to 18.11.4, and from 19.0 prior to 19.0.1 are vulnerable; all later releases contain the fix.
Risk and Exploitability
The CVSS score of 8.2 indicates moderate-to-high severity. EPSS data is unavailable, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. The attack requires a legitimate GitLab account; once authenticated, the user can invoke a Duo AI workflow that the system mistakenly runs under another user’s identity.
OpenCVE Enrichment