Database/Control plane, storage & DevOps
GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rights
Impact
Improper authorization lets an authenticated developer-role user change certain package registry metadata that should require maintainer-level permissions. The GitLab package registry is often the source of the wheels, charts and artifacts that land on GPU nodes, so a lower-privileged account editing registry state touches the supply chain that feeds the fleet. GitLab's record limits this to metadata modification and rates integrity low - it does not describe replacing package content or publishing a new artifact, and no confidentiality or availability impact is claimed. Affects 17.6 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.
Who can reach it
An authenticated GitLab user holding developer-role permissions on the project. Maintainer or owner role is not required; network access to the instance is.
What to do
Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), no node drain. Afterwards, review package registry metadata changes made by developer-role accounts over the affected window.
References
Related entries
- Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSACVE-2024-45678 · Infineon cryptographic library (ECDSA) in security microcontrollersMedium
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aCVE-2025-66433 · HTCondor (condor_schedd / Access Point)Medium
- Sealed Secrets controller: unauthenticated template oracle recovers sealed secret plaintextCVE-2026-59341 · Bitnami Sealed Secrets controller (/v1/verify and /v1/rotate HTTP endpoints)Medium
- Apache Airflow 3.3.0-3.3.1: cookie wins over explicit bearer token, misattributing API calls and audit recordsCVE-2026-82355 · Apache Airflow core API (session cookie vs bearer token precedence)Medium
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionCVE-2026-84657 · Jenkins core (build CLI command, -s flag skips Item/Cancel check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.