Database/Control plane, storage & DevOps
GitLab CE/EE: linked work items in a visible epic expose private issue titles and descriptions
Impact
Authorization checks are missing on linked work items reachable through an epic the user can see, so an authenticated user can read child issue titles and descriptions from projects they have no access to. On a shared GitLab instance running a datacenter's build and deployment pipelines, that leaks the content of private planning and incident issues across project boundaries - including whatever infrastructure detail happens to be written in them. Read-only disclosure; separate from the security-policy authorization bug fixed in the same patch release, with a different code path and affected version range.
Who can reach it
Any authenticated GitLab user who can view an epic that links the private child issues. No elevated role needed.
What to do
Upgrade to GitLab 19.2.7, 19.3.3, or 19.4.1; versions from 19.0 before those are affected, CE and EE alike. Normal GitLab patch upgrade and service restart - no node drain or reboot.
References
Related entries
- Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSACVE-2024-45678 · Infineon cryptographic library (ECDSA) in security microcontrollersMedium
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aCVE-2025-66433 · HTCondor (condor_schedd / Access Point)Medium
- Sealed Secrets controller: unauthenticated template oracle recovers sealed secret plaintextCVE-2026-59341 · Bitnami Sealed Secrets controller (/v1/verify and /v1/rotate HTTP endpoints)Medium
- Apache Airflow 3.3.0-3.3.1: cookie wins over explicit bearer token, misattributing API calls and audit recordsCVE-2026-82355 · Apache Airflow core API (session cookie vs bearer token precedence)Medium
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionCVE-2026-84657 · Jenkins core (build CLI command, -s flag skips Item/Cancel check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.