CVE-2026-92470
Beschrijving NL
GitLab heeft een probleem opgelost in GitLab EE dat van invloed was op alle versies van 18.7 vóór 19.2.7, 19.3 vóór 19.3.3 en 19.4 vóór 19.4.1, waardoor een geverifieerde gebruiker onder bepaalde omstandigheden toegang had kunnen krijgen tot gevoelige CI/CD-variabele waarden van foutopsporingsmodi via de Duo AI-probleemoplossingsfunctie vanwege ontbrekende autorisatiecontroles.
Origineel (Engels) tonen
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces through the Duo AI troubleshooting feature due to missing authorization checks.