gitlab-ce is vulnerable to Incorrect Authorization
85
High Risk
Scheduled Pipeline Execution Policy tests do not adequately validate scope before running. An authenticated Developer can execute a policy test pipeline on projects in their group and access protected CI/CD variables that should be limited to higher-privileged roles. The fix tightens scope validation for policy test pipelines so Developers cannot reach those protected variables.
You are affected if you are using a version that falls within the vulnerable range and use Pipeline Execution Policies with protected CI/CD variables.
gitlab-ce is vulnerable to Incorrect Authorization in versions 19.0.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.
Upgrade the gitlab-ce library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.