Database/Control plane, storage & DevOps
GitLab EE: Duo AI troubleshooting exposes CI/CD variable values from debug job traces
Impact
Missing authorization checks in the Duo AI troubleshooting feature let an authenticated user read sensitive CI/CD variable values out of debug-mode job traces. For a fleet whose builds and deploys run through GitLab, those variables are typically the registry credentials, cloud and Kubernetes service-account tokens, and signing keys that the pipeline uses to push images and reconcile clusters - so the payoff is credentials into the GPU cluster's supply chain rather than anything on the GPU node itself. Exposure is limited to jobs that ran with debug tracing enabled.
Who can reach it
Any authenticated GitLab user who can reach the Duo troubleshooting feature on affected projects; low privileges, network-reachable, no user interaction.
What to do
Upgrade to GitLab EE 19.2.7, 19.3.3 or 19.4.1 (affected: 18.7 up to those releases). Self-managed instances: patch and restart GitLab. Treat any CI/CD variable that appeared in a debug trace on an affected version as exposed and rotate it - the upgrade does not undo prior disclosure.
References
Related entries
- GlusterFS (brick, mknod): Mknod can create device nodes that point at real devices on the storage server, so a clientCVE-2018-10923 · GlusterFS (brick, mknod)High
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsCVE-2024-21985 · NetApp ONTAP 9 role-based access controlHigh
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesCVE-2025-3744 · HashiCorp Nomad EnterpriseHigh
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterCVE-2026-45726 · Sidero Omni (ImportedClusterSecrets resource access rules)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.