GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: a developer removed from a project can still push commits via merge request collaboration settings

CVSS 3.1CVE-2025-14562Control plane, storage & DevOpscurated

Impact

Offboarding is the control that makes a CI/CD system trustworthy. Missing authorization checks on merge request collaboration settings let a user who had developer role keep committing after their membership was revoked, so a departed contractor or a rotated-out account can still put code into a branch that pipelines build and deploy onto GPU nodes - container images, driver installers, cluster manifests. The exposure is integrity of the repository that feeds the fleet, not confidentiality. GitLab scores it 3.1 with high attack complexity, so it is a hardening upgrade rather than an emergency.

Who can reach it

Authenticated user who previously held developer-role permissions on the project, over the network. Requires the specific merge request collaboration condition GitLab does not fully describe.

What to do

Upgrade to GitLab 19.0.5, 19.1.3 or 19.2.1 (affected from 10.6) and restart the application - a routine GitLab upgrade, no node maintenance. Afterwards, audit recent commits and pipeline runs on projects where members were removed while merge requests were open.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.