{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2370.json"
      }
    ],
    "title": "GitLab: GitLab: Improper authorization allows credential disclosure and GitLab app impersonation",
    "tracking": {
      "current_release_date": "2026-06-30T04:13:24+00:00",
      "generator": {
        "date": "2026-06-30T04:13:24+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-2370",
      "initial_release_date": "2026-03-29T23:33:44.410000+00:00",
      "revision_history": [
        {
          "date": "2026-03-29T23:33:44.410000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-03-30T15:50:06+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T04:13:24+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "OpenShift Pipelines",
                "product": {
                  "name": "OpenShift Pipelines",
                  "product_id": "openshift_pipelines",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_pipelines:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "OpenShift Pipelines"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Container Platform 4",
                "product": {
                  "name": "Red Hat OpenShift Container Platform 4",
                  "product_id": "red_hat_openshift_container_platform_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Container Platform 4"
          },
          {
            "category": "product_version",
            "name": "openshift-pipelines/pipelines-console-plugin-rhel9",
            "product": {
              "name": "openshift-pipelines/pipelines-console-plugin-rhel9",
              "product_id": "openshift-pipelines/pipelines-console-plugin-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/pipelines-console-plugin-rhel9?repository_url=registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift4/ose-console",
            "product": {
              "name": "openshift4/ose-console",
              "product_id": "openshift4/ose-console",
              "product_identification_helper": {
                "purl": "pkg:oci/ose-console?repository_url=registry.redhat.io/openshift4/ose-console"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift4/ose-console-rhel9",
            "product": {
              "name": "openshift4/ose-console-rhel9",
              "product_id": "openshift4/ose-console-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/ose-console-rhel9?repository_url=registry.redhat.io/openshift4/ose-console-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines",
          "product_id": "openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9"
        },
        "product_reference": "openshift-pipelines/pipelines-console-plugin-rhel9",
        "relates_to_product_reference": "openshift_pipelines"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console-rhel9 as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9"
        },
        "product_reference": "openshift4/ose-console-rhel9",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-2370",
      "cwe": {
        "id": "CWE-233",
        "name": "Improper Handling of Parameters"
      },
      "discovery_date": "2026-03-30T00:01:16.632185+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9",
            "red_hat_openshift_container_platform_4:openshift4/ose-console",
            "red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2452920"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in GitLab CE/EE. An authenticated user with minimal workspace permissions could exploit an improper authorization check within Jira Connect installations to obtain installation credentials and impersonate the GitLab application. This vulnerability could lead to unauthorized access and control over the GitLab app.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "GitLab: GitLab: Improper authorization allows credential disclosure and GitLab app impersonation",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9",
          "red_hat_openshift_container_platform_4:openshift4/ose-console",
          "red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-2370"
        },
        {
          "category": "external",
          "summary": "RHBZ#2452920",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452920"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-2370",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2370"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-2370",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2370"
        },
        {
          "category": "external",
          "summary": "https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/",
          "url": "https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/"
        },
        {
          "category": "external",
          "summary": "https://gitlab.com/gitlab-org/gitlab/-/work_items/589635",
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/589635"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/3522829",
          "url": "https://hackerone.com/reports/3522829"
        }
      ],
      "release_date": "2026-03-29T23:33:44.410000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9",
            "red_hat_openshift_container_platform_4:openshift4/ose-console",
            "red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9",
            "red_hat_openshift_container_platform_4:openshift4/ose-console",
            "red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9"
          ]
        }
      ],
      "title": "GitLab: GitLab: Improper authorization allows credential disclosure and GitLab app impersonation"
    }
  ]
}