Database/Control plane, storage & DevOps
GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted user
Impact
Improper sanitization of user-controlled data in the Markdown JSON table renderer lets an authenticated user craft content that, when viewed, induces a targeted user's browser into unintended state-changing requests against GitLab. On a self-hosted GitLab that drives fleet CI/CD, the targeted user is often a maintainer or admin, and state-changing requests in their session mean pipeline, runner, token and membership changes - which is a path into whatever those pipelines deploy on the GPU fleet. GitLab rates it with a scope change and high confidentiality and integrity impact. The advisory does not describe the specific requests an attacker can force.
Who can reach it
Network, authenticated attacker (any user who can post Markdown), plus user interaction - the victim must view the crafted content. Affects all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
What to do
Upgrade self-managed GitLab to 19.3.2, 19.2.6 or 19.1.8 depending on your branch. Standard GitLab patch release: application upgrade and service restart, no node reboot, though it is a maintenance window for everything that depends on the instance's CI. GitLab.com is already patched.
References
Related entries
- Ceph RGW (SigV4 signature verifier): Anyone handed a single presigned PUT URL gets more authority than whoever signedNCVD-2026-039-ceph-rgw-sigv4-signature-verifie · Ceph RGW (SigV4 signature verifier)High
- Ceph MON (config-key store, MMonSubscribe handler): MULTI-TENANT ISOLATION AND HOST COMPROMISE: one craftedNCVD-2026-041-ceph-mon-config-key-store-mmonsu · Ceph MON (config-key store, MMonSubscribe handler)High
- Ceph MON (ceph-mon): The monitor accepts pool create/delete and snapshot operations from any authenticated user thatCVE-2018-10861 · Ceph MON (ceph-mon)High
- GlusterFS (brick, gfs3_mknod_req): A crafted mknod RPC traverses out of the volume and writes a file anywhere the brickCVE-2018-10926 · GlusterFS (brick, gfs3_mknod_req)High
- Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): A logic error in MKA over EAP-TLS lets an unauthenticatedCVE-2018-15372 · Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS)High
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupCVE-2021-23214 · PostgreSQLHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.