MEDIUM

CVE-2023-1710

Gitlab GitLab 2023-04-05 CVSS v3.1
CVSS
5.3

Description

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

Summary dbcve.org

This GitLab vulnerability allows attackers to view the count of internal (confidential) notes on issues through improper API access controls. Internal notes are typically used for sensitive discussions not visible to regular users, and revealing their existence/count provides reconnaissance value to attackers.

Mitigation

Upgrade GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later to patch the access control flaw that allows unauthorized viewing of internal note counts.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.79%
Probability of exploitation in next 30 days
54.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE