Impact
A flaw in GitLab allows an authenticated user to bypass expected proxy checks and read internal data emission endpoints that expose credentials and tokens. It results from missing authorization verification and can reveal who can reach those endpoints, compromising the confidentiality of the GitLab instance.
Affected Systems
The vulnerability affects GitLab Community Edition and Enterprise Edition from version 10.1.0 up to, but not including, 19.1.8, 19.2.6, and 19.3.2. Upgrading to GitLab 19.1.8, 19.2.6, 19.3.2 or any later release mitigates the issue.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. The EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires endpoints; once authenticated, an attacker can read credentials that should otherwise be filtered through a proxy.
OpenCVE Enrichment