CVE-2026-8937 GitLab CE/EE 授权缺失漏洞
影响认证用户可越权读取无权访问项目的私有子议题内容
CVE-2026-8937 是 GitLab CE/EE 中的一个授权缺失漏洞。在可见 Epic 中关联的工作项缺少必要的权限校验,导致已认证用户可读取其本无权访问项目下的私有子议题标题与描述。官方已发布修复版本。
影响范围
影响 GitLab CE/EE 19.0 至 19.2.7 之前、19.3 至 19.3.3 之前、19.4 至 19.4.1 之前的版本。
漏洞详情
漏洞类型为授权缺失(越权访问)。成因是 GitLab 在处理可见 Epic 内关联的工作项时,未对子议题所属项目的访问权限做校验。已认证用户可通过 Epic 关联关系绕过权限边界,读取私有子议题的标题和描述等信息。
利用条件与风险
利用前提是攻击者拥有一个合法 GitLab 账号(认证用户),且目标私有子议题通过可见 Epic 被关联。属于信息泄露类漏洞,CVSS 4.3 为中危,实战中可造成敏感议题内容泄露。
修复建议
官方已在 19.2.7、19.3.3、19.4.1 及后续版本中修复,建议尽快升级。临时缓解措施暂无公开信息。
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.