GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify proj…
High CVSS 7.1
Summary
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/ Release Notes
- https://gitlab.com/gitlab-org/gitlab/-/work_items/606580 Broken Link
- https://hackerone.com/reports/3775445 Permissions Required
Timeline
- nvd_ingest NVD