gitlab-ce is vulnerable to Incorrect Authorization
77
High Risk
The CI/CD environment variable scope pattern matcher does not validate inputs correctly. An authenticated user can access CI/CD variables outside their intended environment scope. The fix validates environment scope patterns so variables cannot be matched outside the intended scope.
You are affected if you are using a version that falls within the vulnerable range and use environment-scoped CI/CD variables.
gitlab-ce is vulnerable to Incorrect Authorization in versions 15.7.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.
Upgrade the gitlab-ce and/or the gitlab-ee library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.