MEDIUM
CVE-2023-1710
CVSS
5.3
Description
A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.
Summary dbcve.org
This GitLab vulnerability allows attackers to view the count of internal (confidential) notes on issues through improper API access controls. Internal notes are typically used for sensitive discussions not visible to regular users, and revealing their existence/count provides reconnaissance value to attackers.
Mitigation
Upgrade GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later to patch the access control flaw that allows unauthorized viewing of internal note counts.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.79%
Probability of exploitation in next 30 days
54.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.