4.3

CVE-2026-92530

Use of Less Trusted Source in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance due to improper reliance on ephemeral cache state during Direct Transfer imports.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 19.1.0 < 19.2.7
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.1.0 < 19.2.7
Gitlab ≫ GitLab SwEdition community Version >= 19.3.0 < 19.3.3
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.3.0 < 19.3.3
Gitlab ≫ GitLab Version 19.4.0 SwEdition community
Gitlab ≫ GitLab Version 19.4.0 SwEdition enterprise
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@gitlab.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-348 Use of Less Trusted Source

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/
Vendor Advisory
Release Notes
https://gitlab.com/gitlab-org/gitlab/-/work_items/628379
Broken Link