CyberRota Analysis
AI-GeneratedGitLab versions prior to 19.1.3 and 19.2.1 are vulnerable to an issue that may allow authenticated users to access unauthorized project information through the AI-assisted code review feature due to improper handling of untrusted content. This could lead to information disclosure, impacting the confidentiality of project data. Organizations using affected versions should prioritize updating to the latest releases to mitigate this risk.
Original NVD Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.
Related CVEs
Other vulnerabilities affecting the same vendor(s)