Impact
The vulnerability is a missing authorization check that allows an unauthorized user to view project import source information, thereby enabling disclosure of potentially sensitive configuration or source code metadata. The weakness is identified as CWE‑863 and results in a unilateral breach of confidentiality.
Affected Systems
GitLab Community Edition and Enterprise Edition installations running any release from 16.6 up to but excluding the patched releases 19.0.5, 19.1.3, and 19.2.1 are affected. All earlier releases prior to 16.6 are not impacted.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, which suggests a low likelihood of exploitation at this time. Based on the description, it is inferred that an attacker only needs to authenticate to the GitLab instance and then can trigger the missing authorization check, resulting in the retrieval of import source data through the exposed API endpoint.
OpenCVE Enrichment