Impact
The vulnerability lies in GitLab’s Generic Package Registry, where an authenticated user with a developer role can replace package file content and hide packages from their owners because authorization checks are inadequate. This allows the user to tamper with package distribution and potentially conceal malicious or altered releases, undermining the integrity of the package pipeline.
Affected Systems
Affected systems are GitLab Community and Enterprise Editions. Versions prior to 19.1.8 (for 19.x branches), 19.2 before 19.2.6, and 19.3 before 19.3.2 are vulnerable. Earlier releases from 13.9 onward also fall within the affected range.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV and no active exploitation has been reported. Attackers must have authenticated access with developer permissions compromised developer accounts. The vendor’s patch is the sole official fix; otherwise restricting developer access or monitoring package activity can help mitigate risk.
OpenCVE Enrichment