Database/Control plane, storage & DevOps
GitLab CE/EE: authenticated user can obtain higher-privileged users' credentials and act as them
Impact
Under conditions GitLab does not detail publicly, an authenticated user could obtain credentials belonging to higher-privileged users and then perform actions in their context. For a datacenter that runs GitLab as its CI/CD and GitOps source of truth, that is a privilege escalation into the pipelines that build images and deploy to the fleet, so the blast radius is whatever those higher-privileged accounts can push or deploy. GitLab rates confidentiality and integrity high; exploitation needs user interaction and is rated high complexity. The record gives no mechanism beyond that, so treat the exposure as credential theft within the GitLab instance rather than a specific remote code path.
Who can reach it
An authenticated GitLab user on the instance, plus interaction from a higher-privileged victim user. No pre-existing elevated access is required.
What to do
Upgrade to GitLab 18.4.5, 18.5.3 or 18.6.1 depending on your branch and restart the GitLab services - a single-instance maintenance window, no fleet impact. Rotate tokens and credentials for administrator and maintainer accounts if you suspect exposure, since the flaw yields credentials rather than a session.
References
Related entries
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerCVE-2025-57847 · Red Hat Ansible Automation Platform container images (/etc/passwd permissions)Medium
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsCVE-2026-79717 · galaxy_ng (Ansible Galaxy / Automation Hub server, namespace avatar fetch worker)Medium
- AWX bulk job launch: read-level permission on an instance group is enough to run jobs on itCVE-2026-84470 · Ansible Automation Platform automation-controller (AWX) Bulk Job Launch APIMedium
- Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named fileCVE-2019-9508 · Vertiv Avocent UMG-4000 universal management gatewayMedium
- Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive defaultCVE-2022-31251 · Slurm (openSUSE slurm-testsuite packaging)Medium
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansCVE-2024-20280 · Cisco UCS Central Software (weak backup encryption)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.