Database/Control plane, storage & DevOps
GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user data
Impact
Under conditions GitLab does not detail, an unauthenticated request using a GraphQL directive modifies or deletes public projects and user data. On a self-hosted GitLab that is the system of record for pipeline definitions, infrastructure-as-code, and container build recipes for the fleet, so this is both a data-destruction event and a path to tampering with what CI runners execute on GPU nodes. Integrity and availability are rated high while confidentiality is only low, so the realistic outcome is destruction and modification rather than mass data theft. Affected: 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
Who can reach it
Anyone who can reach the GitLab web endpoint. No authentication, no user interaction. Internet-facing instances are exposed directly; internal-only instances are exposed to anyone on the corporate or management network.
What to do
Upgrade to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as matches your branch. This is a control-plane package upgrade and service restart (for Omnibus, reconfigure and restart), costing a short GitLab outage — no node drain, no impact on running GPU jobs, though queued pipelines will pause for the duration.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.