Impact
GitLab contains an authorization flaw that allows unauthenticated users to determine whether a private project exists by examining cross‑project reference pages. The issue does not provide code execution, elevated privileges, or data leakage beyond knowledge of project existence. It is a case of improper access control, identified as CWE‑862.
Affected Systems
GitLab Community and Enterprise Editions are affected. All releases from 9.1 up to but excluding 18.11.7, from 19.0 up to but excluding 19.0.4, and from 19.1 up to but excluding 19.1.2 are susceptible.
Risk and Exploitability
The CVSS score of 4.3 classifies this vulnerability as low‑medium severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. Because the issue is not listed in the CISA KEV catalog, it is not known to be actively exploited. The attack vector requires no authentication and leverages publicly accessible cross‑project reference endpoints to confirm the existence of a private project.
OpenCVE Enrichment