GitLab CE/EE Jira Integration Access Control Vulnerability

Vulnerability

A vulnerability exists in GitLab CE/EE versions 13.7 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This issue allows authenticated users to view Jira issues beyond the designated project scope. The problem arises because the integration filter only controls display rather than enforcing access restrictions, as intended.

Impact

Exploitation of this vulnerability could lead to unauthorized access to Jira issues outside the user's assigned project scope.

Remediation

Users can upgrade to GitLab versions 18.11.3, 18.10.6, or a version within the 18.9.x range to address this vulnerability.

Added: May 14, 2026, 6:50 AM
Updated: May 14, 2026, 6:50 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
6.2
remediation
7.7
relevance
8.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.