GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
15.11.0
|
19.2.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
15.11.0
|
19.2.7
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
|
19.3.0
|
19.3.3
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
|
19.3.0
|
19.3.3
|
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.4.0:*:*:*:community:*:*:*
|
— | — |
|
Gitlab Gitlab
cpe:2.3:a:gitlab:gitlab:19.4.0:*:*:*:enterprise:*:*:*
|
— | — |