MEDIUM

CVE-2023-0989

Gitlab GitLab 2023-09-29 CVSS v3.1
CVSS
5.7

Description

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

Summary dbcve.org

This is an information disclosure vulnerability in GitLab CE/EE that allows attackers to extract non-protected CI/CD variables by tricking users into visiting a fork containing malicious CI/CD configuration. The attack exploits the trust relationship between users and forked repositories, accessing sensitive variable data that should not be exposed.

Mitigation

Upgrade GitLab to version 16.2.8, 16.3.5, 16.4.1 or later. Additionally, review CI/CD variable configurations to ensure only necessary variables are defined and consider marking sensitive variables as protected.

Weakness (CWE)

CWE-282

EPSS Score

0.43%
Probability of exploitation in next 30 days
36.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE