MEDIUM

CVE-2023-0223

Gitlab GitLab 2023-03-09 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.

Summary dbcve.org

GitLab has an information disclosure vulnerability in its API where release descriptions could be retrieved by non-project members even when release visibility is restricted to project members only. The API fails to properly enforce the visibility settings configured in the project, allowing unauthorized access to sensitive release information.

Mitigation

Upgrade GitLab to version 15.7.9, 15.8.5, or 15.9.3 or later. If immediate upgrade is not possible, restrict API access to trusted users and monitor for unauthorized release description access.

EPSS Score

0.79%
Probability of exploitation in next 30 days
54.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE