Impact
The vulnerability is a command injection flaw in GitLab Enterprise Edition introduced by an overflow of the Unicode conversion buffer during Advanced Search indexing. An authenticated user who imports a specially crafted Git project export can trigger this overflow, leading to arbitrary code execution on the GitLab server. The flaw is limited to situations where the imported data triggers the Unicode conversion process and requires user authentication, meaning that users with any level of access that can upload an export file may be able to exploit it.
Affected Systems
GitLab hosts running Enterprise Edition are impacted. Versions from 12.3 through 19.1.8, 19.2 editions prior to 19.2.6, and 19.3 editions prior to 19.3.2 are vulnerable. All builds below the identified patch levels are at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The flaw is listed as not present in CISA KEV, but its high intrinsic value and requirement for only authenticated access make it attractive to attackers. The likely attack vector involves a legitimate user account uploading an export file; no remote code execution is possible without such a credential, but the exploit enables full compromise of the GitLab instance.
OpenCVE Enrichment