Database/Control plane, storage & DevOps
GitLab EE: Duo Chat GraphQL subscription leaks Advanced Search config and credentials
Impact
An authenticated user with Duo Chat access can pass a crafted GraphQL subscription argument that bypasses serialization and performs a server-side object lookup, returning Advanced Search instance configuration and the credentials embedded in it. That typically means the Elasticsearch/OpenSearch endpoint and its authentication material, which in a self-managed deployment often sits on the same internal network as the rest of the CI and artifact infrastructure. Any developer account on the instance is enough, so this converts ordinary user access into instance-level secret disclosure.
Who can reach it
Any authenticated GitLab user who has Duo Chat enabled for them, over the normal web/GraphQL endpoint. No admin role required.
What to do
Upgrade to GitLab 19.1.8, 19.2.6 or 19.3.2 (EE versions from 18.3 onward are affected) and restart the application. Rotate the Advanced Search credentials afterwards, since the fix does not invalidate anything already disclosed. Disabling Duo Chat removes the exposed path if an upgrade window is not available immediately.
References
Related entries
- lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addressesCVE-2015-8011 · lldpd (lldp_decode, management addresses)Critical
- Lantronix xPrintServer: The device ships with a hardcoded root account baked into every unit of a given firmware lineCVE-2016-4325 · Lantronix xPrintServerCritical
- HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoSCVE-2016-4375 · HPE iLO3 / iLO4Critical
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCVE-2017-5689 · Intel Active Management Technology / Standard ManageabilityCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.