
PEACH
Un framework di isolamento del tenant
CVE-2026-4523 is a missing authorization vulnerability in GitLab CE/EE that allows unauthenticated attackers to read CI/CD job trace contents containing sensitive variable values via the GraphQL API. It affects all GitLab versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The vulnerability was disclosed and patched on September 29, 2026. It carries a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory, GitLab Patch Release).
The root cause is improper authorization enforcement (CWE-862: Missing Authorization) in GitLab's GraphQL API. Under certain conditions, the API fails to properly validate whether a requesting user has the necessary permissions to access CI/CD job trace data, allowing unauthenticated network requests to retrieve job trace contents. The attack vector is network-based with high attack complexity, requiring no privileges or user interaction, but exploitation is conditional on specific circumstances that are not fully disclosed. The vulnerability was originally reported via HackerOne (GitHub Advisory, HackerOne Report).
Successful exploitation allows an unauthenticated attacker to read CI/CD job trace contents that may contain sensitive variable values such as API keys, credentials, tokens, or other secrets embedded in pipeline logs. The confidentiality impact is limited in scope (low), with no integrity or availability impact. However, exposure of CI/CD secrets could enable further attacks such as unauthorized access to downstream systems, supply chain compromise, or lateral movement within an organization's infrastructure (GitHub Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the disclosure date (GitHub Advisory). The EPSS score is approximately 0.345%, placing it in the 26th percentile for exploitation probability within 30 days. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/api/v4/version if accessible)./api/graphql) querying CI/CD job trace data from external or unexpected IP addresses; unusual volume of GraphQL queries targeting job trace fields without authentication headers.jobTrace or similar fields from unauthenticated sessions; repeated access attempts to job trace data from the same source IP.GitLab has released patched versions 19.2.7, 19.3.3, and 19.4.1 addressing this vulnerability. Users should upgrade to the appropriate fixed version based on their current release branch. As an interim workaround if immediate patching is not possible, administrators should restrict network access to the GitLab GraphQL API endpoint and monitor for unauthorized access attempts to CI/CD job traces. Additionally, avoid printing sensitive variable values directly in CI/CD job logs as a defense-in-depth measure (GitLab Patch Release, GitHub Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."