Database/Control plane, storage & DevOps
GitLab: a developer removed from a project can still push commits via merge request collaboration settings
Impact
Offboarding is the control that makes a CI/CD system trustworthy. Missing authorization checks on merge request collaboration settings let a user who had developer role keep committing after their membership was revoked, so a departed contractor or a rotated-out account can still put code into a branch that pipelines build and deploy onto GPU nodes - container images, driver installers, cluster manifests. The exposure is integrity of the repository that feeds the fleet, not confidentiality. GitLab scores it 3.1 with high attack complexity, so it is a hardening upgrade rather than an emergency.
Who can reach it
Authenticated user who previously held developer-role permissions on the project, over the network. Requires the specific merge request collaboration condition GitLab does not fully describe.
What to do
Upgrade to GitLab 19.0.5, 19.1.3 or 19.2.1 (affected from 10.6) and restart the application - a routine GitLab upgrade, no node maintenance. Afterwards, audit recent commits and pipeline runs on projects where members were removed while merge requests were open.
References
Related entries
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerCVE-2026-44778 · Inspektor Gadget uprobetracer USDT note parser (pkg/uprobetracer/usdt.go)Low
- Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only typesCVE-2026-70430 · Jenkins core (project naming strategy configuration)Low
- Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validationCVE-2025-55703 · Sunbird Power IQ 9.2.0 APILow
- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyCVE-2024-23591 · Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode)Low
- Linuxfabrik monitoring plugins: symlink attack on predictable /tmp SQLite caches lets a local user write as rootCVE-2026-53759 · linuxfabrik-lib db_sqlite.py (Monitoring Plugins cache databases in /tmp)Low
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteNCVD-2026-012-qct-quanta-cloud-technology-serv · QCT (Quanta Cloud Technology) server security centreUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.