Executive brief
GitLab has fixed a security issue in its Community and Enterprise editions that could allow a logged-in user to access Continuous Integration (CI) data they were not intended to see. GitLab is a platform used by software teams to manage code and automate the building and testing of applications. If exploited, an attacker could view sensitive build information or pipeline data from different branches or reference types within the system.
Technical details
An information disclosure vulnerability exists in GitLab CE/EE versions 12.7 through 19.0.1 due to the use of an incorrectly-resolved name or reference (CWE-706). Under specific conditions, an authenticated attacker can bypass intended access controls to retrieve Continuous Integration (CI) data from a different 'ref' type than what was originally authorized. The vulnerability is reachable over the network with low privileges and requires no user interaction. GitLab has released patches in versions 18.10.7, 18.11.4, and 19.0.1 to address this issue.
Affected products
- GitLab GitLab CE/EE 12.7 to 18.10.7, 18.11 to 18.11.4, 19.0 to 19.0.1
Timeline
- 2026-05-27: disclosed
- 2026-05-27: patched
- 2026-05-27: advisory