CVE-2023-0223
Description
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.
Summary dbcve.org
GitLab has an information disclosure vulnerability in its API where release descriptions could be retrieved by non-project members even when release visibility is restricted to project members only. The API fails to properly enforce the visibility settings configured in the project, allowing unauthorized access to sensitive release information.
Mitigation
Upgrade GitLab to version 15.7.9, 15.8.5, or 15.9.3 or later. If immediate upgrade is not possible, restrict API access to trusted users and monitor for unauthorized release description access.