MEDIUM

CVE-2023-2478

Gitlab GitLab 2023-05-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab's GraphQL API where an unauthorized or malicious user can register and attach a runner to any project by exploiting the GraphQL endpoint. Since CI/CD runners can execute arbitrary commands and access sensitive environment variables and secrets, a malicious runner attached to projects could expose credentials, steal code, or compromise the build pipeline.

Mitigation

Upgrade GitLab to version 15.9.7, 15.10.6, 15.11.2 or later. Additionally, audit existing runners to identify and remove any unauthorized or suspicious runners attached to projects.

Weakness (CWE)

CWE-732 Incorrect Permission Assignment

EPSS Score

5.04%
Probability of exploitation in next 30 days
91.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE