Impact
The vulnerability is an authorization bypass that allows an authenticated GitLab user to prevent another user from modifying group settings when group URL slugs are improperly validated during namespace transfers. This flaw is an instance of improper authorization ( an unauthorized denial of service against another user’s group configuration capabilities. The attacker does not gain broader system privileges but can effectively restrict the target’s ability to modify group settings, impacting the integrity of group management functions.
Affected Systems
Affected products include GitLab Community Edition and Enterprise Edition versions from 13.0 through 19.1.7, 19.2.0 through 19.2.5, and 19.3.0 through 19.3.1. The vulnerability exists in the logic handling group URL slug validation during namespace transfer operations.
Risk and Exploitability
The CVSS score of 4.3 indicates service or privilege restriction. The EPSS score of less than 1% means exploitation is deemed unlikely at present. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to be an authenticated GitLab user and to initiate a namespace validation. Because the flaw only causes a denial of group modification capability, it does not lead to remote code execution or data exfiltration and is limited to users with access to the relevant group settings.
OpenCVE Enrichment