Impact
GitLab identifies a defect in its Package Registry component that, under certain conditions, allows an authenticated user with a developer role to alter metadata of packages that normally require maintainer‑level permissions. This flaw falls under CWE‑863 – Improper Authorization. An attacker who can assume a developer account can make unauthorized changes to package metadata, potentially affecting package integrity and the trust of downstream consumers. The vulnerability does not provide a direct path to arbitrary code execution but does enable privilege escalation within the scope of package metadata management.
Affected Systems
The issue affects GitLab Community Edition and Enterprise Edition installations across multiple major releases. Specifically, all versions newer than or equal to 17.6 and older than 19.0.6, 19.1.x before 19.1.4, and 19.2.x before 19.2.2 are impacted. Users operating on any of these versions should verify whether they are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity level. Because exploitation requires authentication with a developer‑level account, external attackers face a limited attack surface; however, insider threat or compromised credentials remain viable risks. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no widespread exploitation is currently documented. Nonetheless, the ability to modify package metadata without proper authorization presents a significant risk to the integrity of the software supply chain within affected GitLab environments.
OpenCVE Enrichment