Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6352

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

A flaw was found in GitLab Enterprise Edition (EE). An authenticated user with auditor-level access could modify compliance violation records. This was possible due to improper authorization on certain GraphQL operations, allowing them to bypass intended access controls.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2498312gitlab: GitLab EE: Auditor-level users can modify compliance records via improper authorization in GraphQL

EPSS

Процентиль: 18%
0.00264
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
ubuntu
22 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

CVSS3: 2.7
nvd
22 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

CVSS3: 2.7
github
22 дня назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.

EPSS

Процентиль: 18%
0.00264
Низкий

2.7 Low

CVSS3