- Description
- GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 8.2
- Impact score
- 5.8
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- Severity
- HIGH
- cve@gitlab.com
- CWE-639
- Hype score
- Not currently trending
GitLab の7 件の脆弱性が FIX:Duo AI ワークフローのアクセス制御不備などに対処 https://t.co/fnxEBTx1KB 今回のアップデートでは、ユーザーの ID 解決や認可チェックといった、システムの根幹に関わる処理の不備に対
@iototsecnews
5 Jun 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLab publicó las versiones 19.0.1, 18.11.4 y 18.10.7 (CE/EE) que corrigen 7 vulnerabilidades, destacando CVE-2026-4868 (CVSS 8.2) , CVE-2026-2710, y CVE-2026-1402 (CVSS 6.5). Más información: https://t.co/de1hLcFTkW https://t.co/ExghQ2wtcq
@CSIRT_Telconet
31 May 2026
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "E1F4CEEB-95BD-4BFE-9316-403106E919EC",
"versionEndExcluding": "18.10.7",
"versionStartIncluding": "18.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F4085D50-86E4-4FC7-BB90-5181E6E65DEC",
"versionEndExcluding": "18.11.4",
"versionStartIncluding": "18.11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:19.0.0:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "57A0D68B-909C-416E-8EAE-A14886F4ABA9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]