GitLab устранил проблему в GitLab CE/EE, затрагивающую все версии с 19.0 до 19.0.6, с 19.1 до 19.1.4 и с 19.2 до 19.2.2, которая при определенных условиях могла позволить аутентифицированному пользователю с разрешениями роли разработчика выполнять конвейеры CI/CD в защищенной ветке без необходимых разрешений push из-за неправильной авторизации при проверке ссылок на конвейер.
Показать оригинальное описание (EN)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 6
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.0.0
|
19.0.6
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.0.0
|
19.0.6
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.1.0
|
19.1.4
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.1.0
|
19.1.4
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.2.0
|
19.2.2
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.2.0
|
19.2.2
|