Impact
GitLab had a deserialization flaw (CWE-502) that could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials by crafting a specially crafted GraphQL subscription argument to bypass serialization and perform a server-side object lookup. This enables the attacker to retrieve confidential configuration information directly.
Affected Systems
GitLab Enterprise Edition is impacted. Versions 18.3 through 18.11.11, 19.0 through 19.0.8, 19.1 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1 contain the flaw. The recommended mitigation is to upgrade to GitLab EE 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2, or any newer release.
Risk and Exploitability
The CVSS score of 9.9 marks this as an extremely high risk vulnerability. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and though it is not listed in CISA's KEV catalog, its exploitability requires only an authenticated user with Duo Chat privileges. Attackers would need to send a specially crafted GraphQL subscription request to trigger the bypass, indicating an authenticated, internal attack vector.
OpenCVE Enrichment