GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*
- >= 18.2, < 18.7.6
- >= 18.8, < 18.8.6
- >= 18.9, < 18.9.2
A vulnerability exists in GitLab Enterprise Edition (EE) versions 18.2 prior to 18.7.6, 18.8 prior to 18.8.6, and 18.9 prior to 18.9.2. This vulnerability allows an authenticated user to access Virtual Registry data in groups where they are not members, due to improper authorization under certain conditions.
Exploitation of this vulnerability could lead to unauthorized access to Virtual Registry data in certain groups.
Users are advised to upgrade to GitLab EE versions 18.9.2, 18.8.6, or 18.7.6.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.