Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.
Problem types
CWE-863: Incorrect Authorization
Product status
18.3 before 18.3.4
18.4 before 18.4.2
Credits
This vulnerability has been discovered internally by GitLab team member Brian Williams.
References
about.gitlab.com/...08/patch-release-gitlab-18-4-2-released/
gitlab.com/gitlab-org/gitlab/-/issues/567847 (GitLab Issue #567847)