Database/Control plane, storage & DevOps
GitLab EE: Owner or Maintainer can silently disable protected-environment deployment approvals
Impact
Access control on protected environments was checked after the resource had already been modified, so a user with Owner or Maintainer permissions could turn off deployment approval requirements without the change being blocked or surfaced. Unapproved deployments then reach production. Where GitLab environments gate deploys to a GPU cluster - node images, driver rollouts, GPU Operator or model-serving manifests - this removes the four-eyes control on exactly the changes that can take a fleet down, and it does so quietly. It requires a high-privilege account already, so the realistic threat is a compromised maintainer credential or an insider, not an outside attacker.
Who can reach it
An authenticated GitLab EE user with Owner or Maintainer permissions on the group or project, over the network. High privilege required.
What to do
Upgrade self-managed GitLab EE to 19.1.8, 19.2.6, or 19.3.2 (affected from 17.1). Package upgrade and service restart on the GitLab host. After upgrading, audit protected-environment approval settings and recent deployments for approval rules that were disabled while the flaw was live.
References
Related entries
- Grafana: A user can block another user's login by registering their email address as a usernameCVE-2022-39229 · GrafanaMedium
- Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access andCVE-2023-31042 · Pure Storage FlashBlade object store protocolMedium
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationCVE-2023-31203 · OpenVINO Model ServerMedium
- Kibana: Open redirect leading to SSRF via a specially crafted URLCVE-2025-25012 · KibanaMedium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.