Database/Control plane, storage & DevOps
GitLab EE: authenticated user can view restricted group configuration settings
Impact
Improper authorization checks on a group settings page let an authenticated user view configuration settings that should be restricted to higher-privileged roles. For a self-managed GitLab driving fleet CI/CD, group settings describe integrations, runner and compliance configuration - useful reconnaissance for an account already inside the instance, but the record describes viewing only. GitLab rates confidentiality low with no integrity or availability impact, and does not say which settings are exposed. Affects 17.7 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.
Who can reach it
An authenticated GitLab user reaching the group settings page over the network. No elevated role is required beyond whatever access the group already grants.
What to do
Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), with a short GitLab outage and no fleet impact.
References
Related entries
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
- GitLab EE: developer-role user can read external status check configuration for a merge requestCVE-2026-4879 · GitLab EE (merge request external status check API)Medium
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingCVE-2026-53437 · Jenkins core (post-login redirect URL validation)Medium
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataCVE-2026-6821 · GitLab EE (merge requests API, IP-based access restrictions)Medium
- Jenkins: symlinks with empty names in agent tar archives write arbitrary files on the controllerCVE-2026-70427 · Jenkins controller (tar and tar.gz extraction of agent-supplied archives)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.