Impact
GitLab Enterprise Edition contained a logic flaw (CWE-863) that could allow an authenticated user and, during its execution, read protected CI/CD variables that were intended to be visible only to higher‑privileged roles. The underlying problem was insufficient scope validation when accessing those variables.
Affected Systems
All GitLab Enterprise Edition releases in the 19.0, 19.2, and 19.3 series are affected. Specifically, any 19.0 release before 19.1.8, any 19.2 release before 19.2.6, and any 19.3 release before 19.3.2 are vulnerable. The issue applies to users who hold a developer role within that group.
Risk and Exploitability
The CVSS base score of 8.5 classifies this flaw as high risk, while the EPSS score of < 1% indicates a very low probability of exploitation at present. Based on the description, the likely attack vector is authenticated access within an organization’s internal network. If an attacker can trigger a policy test pipeline, they can read protected CI/CD variables that are intended for higher‑privileged roles. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment