Impact
In certain GitLab Enterprise Edition releases, an authenticated user with Owner or Maintainer permissions could silently disable protected environment deployment approval requirements. This action allows projects production, effectively bypassing the intended deployment gate and exposing the organization to unauthorized code. The flaw is an improper access control check performed after a protected resource modification, classified as CWE‑1280.
Affected Systems
The vulnerability exists in all GitLab EE versions from 17.1 up to but not including 19.1.8, 19.2.6, and 19.3.2. Users running any pre‑19.1.8, pre‑19.2.6, or pre‑19.3.2 release of GitLab EE are affected unless CIs have been patched.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate risk, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time not listed in the CISA KEV catalog. Attackers need authenticated access and an Owner or Maintainer role to abuse the flaw, meaning exploitation requires privilege escalation or credential compromise. While the flaw does not allow arbitrary remote code execution, it permits unapproved deployments that could disrupt services or introduce malicious code.
OpenCVE Enrichment