{
  "repository": "https://gitlab.com/gitlab-org/gitlab",
  "commit_source": "image_build_metadata",
  "commit_sha": "668508315ee5b5a59aa018424f741c27e81bafe1",
  "notes": "Exact tested source identity resolved from the omnibus image build metadata (/opt/gitlab/version-manifest.txt, component gitlab-rails) of the immutable official Docker image tags. The variant (alternate trigger) was confirmed on the vulnerable 19.3.1 build; the fixed 19.3.2 build was exercised as the bypass negative control. Workhorse route regexes extracted from the shipped binaries are identical between the two versions (see bundle/logs/vuln_variant/workhorse_regexes.txt).",
  "submitted_target": {
    "target_kind": "docker_image",
    "version": "19.3.1-ce.0",
    "ref": "gitlab/gitlab-ce:19.3.1-ce.0",
    "display": "gitlab/gitlab-ce:19.3.1-ce.0 (parent CVE target)"
  },
  "variant_target": {
    "target_kind": "docker_image",
    "commit_sha": "668508315ee5b5a59aa018424f741c27e81bafe1",
    "version": "19.3.1-ce.0",
    "ref": "gitlab/gitlab-ce:19.3.1-ce.0",
    "display": "gitlab/gitlab-ce:19.3.1-ce.0, image digest sha256:f63df4c43029fe91db370609c0b40a1e3585cebd06e3e9637d93a9a3030eb86e, gitlab-rails v19.3.1 build revision 668508315ee5b5a59aa018424f741c27e81bafe1 (variant confirmed on this revision)"
  },
  "fixed_control_target": {
    "target_kind": "docker_image",
    "commit_sha": "34042bf7d00ca54c5e04079df6cdc6151485fd46",
    "version": "19.3.2-ce.0",
    "ref": "gitlab/gitlab-ce:19.3.2-ce.0",
    "display": "gitlab/gitlab-ce:19.3.2-ce.0, image digest sha256:05453dd1d9aba27c2c487613141596868409b4d03247647f7d66cb0b36f321b8, gitlab-rails v19.3.2 build revision 34042bf7d00ca54c5e04079df6cdc6151485fd46 (all variant entry points blocked: HTTP 401)"
  }
}
