Impact
An authorization flaw in GitLab’s GraphQL API permits an authenticated auditor‑level user to modify compliance violation records. The flaw arises from improper enforcement of permission checks on specific operations, allowing the attacker to change data that should otherwise remain immutable, thereby undermining the integrity of compliance reporting. The weakness is reflected in CWEs 639 and 863, indicating a bypass of intended authorization controls and unauthorized access to sensitive data.
Affected Systems
GitLab Enterprise Edition releases beginning with version 18.2 up to, but not including, 18.11.7; all 19.0 releases before 19.0.4; and all 19.1 releases before 19.1.2 are affected. Versions 18.11.7, 19.0.4, 19.1.2 and later contain the fix.
Risk and Exploitability
The CVSS score of 2.7 classifies this vulnerability as low severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is internal, requiring authenticated auditor‑level access, and the scope is confined to data integrity.
OpenCVE Enrichment