Database/Control plane, storage & DevOps
GitLab CE/EE: pipeline creation race lets a developer act in the context of another user's merge request commit
Impact
A race condition in pipeline creation could, under certain conditions, let a user with Developer access have actions run in the context of another user's merge request commit. For a self-hosted GitLab that builds and publishes the images, drivers and model artifacts a GPU fleet runs, that is a CI identity confusion in the pipeline that holds registry and deploy credentials. The advisory does not describe the preconditions in detail and the record notes user interaction is required, so treat this as a CI supply-chain integrity issue whose exploitability depends on local workflow rather than a straightforward remote takeover.
Who can reach it
An authenticated user with Developer access to the project, targeting a merge request; the record's vector indicates user interaction is required and attack complexity is high.
What to do
Upgrade self-managed GitLab to 19.1.8, 19.2.6 or 19.3.2 (all versions from 13.0 are affected) and restart the GitLab services. GitLab.com is already patched. This is an application upgrade, not fleet maintenance; review recent pipeline runs on merge requests if your runners hold privileged credentials.
References
Related entries
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerCVE-2025-57847 · Red Hat Ansible Automation Platform container images (/etc/passwd permissions)Medium
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsCVE-2026-79717 · galaxy_ng (Ansible Galaxy / Automation Hub server, namespace avatar fetch worker)Medium
- AWX bulk job launch: read-level permission on an instance group is enough to run jobs on itCVE-2026-84470 · Ansible Automation Platform automation-controller (AWX) Bulk Job Launch APIMedium
- Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named fileCVE-2019-9508 · Vertiv Avocent UMG-4000 universal management gatewayMedium
- Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive defaultCVE-2022-31251 · Slurm (openSUSE slurm-testsuite packaging)Medium
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansCVE-2024-20280 · Cisco UCS Central Software (weak backup encryption)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.