GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 18.4, < 18.5.5
- >= 18.6, < 18.6.3
- >= 18.7, < 18.7.1
A missing authorization vulnerability has been identified in the GitLab Duo Workflows API, affecting GitLab Enterprise Edition (EE) versions 18.4 prior to 18.5.5, 18.6 prior to 18.6.3, and 18.7 prior to 18.7.1. This vulnerability could have allowed an authenticated user to access and manipulate AI model settings from unauthorized namespaces by altering namespace identifiers in API requests.
Exploitation of this vulnerability could have led to unauthorized access and modification of AI model settings across different namespaces.
Users are advised to upgrade to GitLab versions 18.7.1, 18.6.3, or 18.5.5. Instructions for updating GitLab can be found on the GitLab Update page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.