Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in GitLab's AI Gateway component that could allow an authenticated user to redirect model requests. This could lead to the exposure of sensitive cloud service credentials and private keys.
- Issue: Redirected AI requests could expose cloud credentials.
- Why remember: Affects AI gateway, a common intermediary service.
- Executive takeaway: Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to the GitLab AI Gateway could manipulate its configuration to send model requests to a malicious endpoint. This manipulation is achieved by crafting an inline flow configuration that overrides the HTTP Host header, potentially exposing sensitive cloud credentials.
- Authenticated user with Duo Agent access.
- Crafted inline flow configuration.
- Disclosure of cloud credentials and keys.
Live Threat
Current exploitation, exposure, and threat context
An authenticated user with Duo Agent Platform access could redirect model requests to an externally-controlled endpoint, potentially exposing Google Cloud Vertex cloud service credentials and private signing keys. This could occur when the GitLab AI Gateway processes a crafted inline flow configuration that manipulates the HTTP Host header.
- Cloud service credentials
- Redirected model requests
- Key compromise
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability within GitLab's AI Gateway necessitates coordinated action from platform or infrastructure teams responsible for GitLab deployments, alongside the specific application owners utilizing the AI Gateway. The immediate priority is to identify all instances of the affected GitLab versions, assess their exposure, confirm business criticality, and locate the accountable owner before planning remediation.
- Platform teams should own the issue.
- Verify AI Gateway external reachability and critical assets.
- Plan targeted remediation during a maintenance window.