CyberRota Analysis
AI-GeneratedGitLab versions from 17.6 to 19.0.6, 19.1 to 19.1.4, and 19.2 to 19.2.2 are vulnerable to improper authorization checks, allowing authenticated users with developer roles to modify package registry metadata without appropriate maintainer permissions. This could lead to unauthorized changes in package integrity, potentially impacting the security and reliability of software deployments. Organizations using affected versions should prioritize applying the latest updates to mitigate this risk.
Original NVD Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.