Database/Control plane, storage & DevOps
GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokens
Impact
GitLab's internal data emission endpoints did not enforce the expected authorization, letting a user reach sensitive credentials and tokens without transiting the expected proxy. For a fleet that builds container images, ships model artifacts and deploys cluster manifests out of GitLab, leaked CI credentials and tokens are a path into the registry and the deploy pipeline rather than a contained web-app bug. The record rates confidentiality impact as low with no integrity or availability effect, and GitLab does not publish the endpoint detail; treat it as credential exposure of uncertain breadth. Affects 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
Who can reach it
Network-reachable against the GitLab instance. The vendor summary says an authenticated user, while the scored vector states no privileges required - assume anyone who can reach the instance's HTTP endpoints until GitLab clarifies.
What to do
Upgrade self-managed GitLab to 19.1.8, 19.2.6 or 19.3.2. That is a standard GitLab package upgrade and service restart on the instance, not a fleet-wide action. After upgrading, rotate CI/CD variables, deploy tokens and personal access tokens that the instance held, since the flaw is credential disclosure. GitLab.com is already patched.
References
Related entries
- DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareNCVD-2026-006-dmtf-libspdm-csr-generation-unde · DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls)Medium
- DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOG: A requester reads memory it was never authorisedNCVD-2026-007-dmtf-libspdm-responder-handling · DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOGMedium
- rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rcloneNCVD-2026-041-rclone-rc-server-debug-pprof-han · rclone (rc server, /debug/pprof handler)Medium
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userCVE-2023-0264 · KeycloakMedium
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSCVE-2022-21417 · MySQL ServerMedium
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverCVE-2023-22084 · MySQL ServerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.