CyberRota Analysis
AI-GeneratedGitLab CE/EE versions prior to 19.2.7, 19.3.3, and 19.4.1 are vulnerable to improper authorization enforcement in the GraphQL API, potentially allowing unauthenticated users to access sensitive CI/CD job trace information. While the severity is rated low, organizations using affected versions should prioritize remediation to protect sensitive data from unauthorized access. Users managing CI/CD pipelines in GitLab should take immediate action to update their installations.
Original NVD Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Related CVEs
Other vulnerabilities affecting the same vendor(s)