Home
HIGH: 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NDefault status
unaffected
7.6.0 (semver) before 7.30.0
affected
Description
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
7.6.0 (semver) before 7.30.0
Credits
This vulnerability has been discovered internally by GitLab team member Joern Schneeweisz.
References
gitlab.com/gitlab-org/gitlab/-/issues/538205 (GitLab Issue #538205)