Executive brief
GitLab Enterprise Edition (EE), a platform used for software development and version control, contained a security flaw in its repository mirroring feature. This vulnerability could allow a user with high-level 'Maintainer' permissions to improperly access the stored credentials of another user. If exploited, this could lead to unauthorized access to external systems or repositories linked to the affected GitLab instance.
Technical details
An Insufficiently Protected Credentials vulnerability (CWE-522) exists in GitLab EE's repository mirroring component. The flaw stems from improper authorization controls that fail to adequately restrict access to stored credentials under specific conditions. An authenticated attacker with 'Maintainer' role permissions can exploit this over the network to retrieve credentials belonging to other users. The issue affects GitLab EE versions 9.5 through 18.11.6, 19.0.x before 19.0.4, and 19.1.x before 19.1.2. GitLab has released patches in versions 18.11.7, 19.0.4, and 19.1.2 to remediate this behavior.
Affected products
- GitLab GitLab EE 9.5 before 18.11.7, 19.0 before 19.0.4, 19.1 before 19.1.2
Timeline
- 2026-07-08: advisory
- 2026-07-08: patched