Database/Control plane, storage & DevOps
GitLab EE: developer-role user can read external status check configuration for a merge request
Impact
A merge request API endpoint is missing an authorization check, so a developer-role account can read external status check configuration that is meant for higher-privileged roles. External status checks are how a self-managed GitLab defers merge approval to an outside system, so the configuration names the endpoints and gates standing between a change and the pipelines that build fleet images. The exposure is read-only and GitLab scores confidentiality low; nothing in the record describes altering or bypassing a status check. Affects 16.0 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.
Who can reach it
An authenticated GitLab user with developer-role permissions on the project, over the instance API. No maintainer or owner role is required.
What to do
Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), no node drain. If the disclosed status check endpoints carry their own secrets, rotate them.
References
Related entries
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingCVE-2026-53437 · Jenkins core (post-login redirect URL validation)Medium
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataCVE-2026-6821 · GitLab EE (merge requests API, IP-based access restrictions)Medium
- Jenkins: symlinks with empty names in agent tar archives write arbitrary files on the controllerCVE-2026-70427 · Jenkins controller (tar and tar.gz extraction of agent-supplied archives)Medium
- Jenkins: path traversal in file parameter names writes arbitrary files on the controller filesystemCVE-2026-70428 · Jenkins controller (path traversal in file parameter names)Medium
- GitLab: developer-role user can replace package file content and hide packages from ownersCVE-2026-7514 · GitLab CE/EE (Generic Package Registry authorization)Medium
- Apache Airflow: /assets/events returns asset events for every DAG, ignoring per-DAG access controlCVE-2026-75158 · Apache Airflow core API (/assets/events endpoint)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.