Database/Control plane, storage & DevOps
GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable values
Impact
On a self-hosted GitLab that builds container images, driver bundles or Terraform/Helm rollouts for a GPU fleet, job logs routinely contain expanded CI/CD variables - registry credentials, cloud service-account keys, kubeconfig tokens. Improper authorization in the GraphQL API let an unauthenticated caller read those traces, so any secret that was echoed or leaked into a job log becomes readable without an account. The practical blast radius is whatever those pipeline credentials can reach: the image registry, the cluster the pipeline deploys to, or node provisioning. GitLab rates it 3.7 because exploitation depends on conditions it does not detail (AC:H), but the value of what leaks is set by your own pipeline hygiene, not by the score.
Who can reach it
Network reach to the GitLab instance's GraphQL endpoint. No authentication required. Instances exposed only inside the management network are correspondingly harder to reach.
What to do
Upgrade to GitLab 19.4.1, 19.3.3 or 19.2.7 (all versions from 15.11 are affected) and restart the application - a normal GitLab upgrade window, no fleet impact. Treat it as a possible secret disclosure: rotate any credential that pipelines may have printed into job logs, and re-check that masked/protected variables are actually set that way.
References
Related entries
- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSNCVD-2021-017-nats-server-tls-ciphersuite-sele · NATS server (TLS ciphersuite selection via CLI flags)Low
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM determines whether data exists on aCVE-2020-8588 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs andCVE-2020-8589 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filterCVE-2023-41891 · FlyteAdmin (list endpoints, SQL injection through list filters)Low
- GitLab EE: reporter-role author of a merge request can reset its approval rulesCVE-2026-7487 · GitLab EE (merge request approval rules, authorization check)Low
- Jenkins: Overall/Manage holders can change Appearance configuration reserved for administratorsCVE-2026-84653 · Jenkins core (Appearance configuration page permission checks)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.