Impact
A missing authorization check in the merge request API endpoint allows an authenticated user with developer‑level permissions to retrieve external status check configuration that should be visible only to higher‑privileged roles. The flaw does not provide a direct path to arbitrary code execution or full system compromise, but it does expose sensitive configuration data that could be used for further attacks or insider misuse.
Affected Systems
GitLab Enterprise Edition versions from 16.0 up to 18.x, as well as 19.0.x before 19.0.6, 19.1.x before 19.1.4, and 19.2.x before 19.2.2. The vulnerability applies to the GitLab product released by GitLab Inc. The affected CPE indicates all GitLab EE releases without additional restrictions.
Risk and Exploitability
The CVSS score of 4.3 suggests low overall severity, and the EPSS score is not available, indicating limited data on exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack would require the attacker to be an authenticated developer and to target a specific merge request endpoint—a scenario that is likely confined to internal use and not publicly exploitable. Nevertheless, the missing authorization could lead to unintended disclosure of configuration data, which may aid other attack vectors. The risk is therefore considered low to moderate in most environments, but it should be mitigated promptly to prevent potential misuse in contexts where the external status check data is valuable.
OpenCVE Enrichment