MEDIUM
CVE-2023-3362
CVSS
5.3
Description
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
Summary dbcve.org
GitLab CE/EE versions 16.0 through 16.0.5 and 16.1.0 contain an information disclosure vulnerability where unauthenticated users can access import error details for projects that were imported from GitHub. This occurs due to improper access controls on the import error reporting functionality.
Mitigation
Upgrade GitLab to version 16.0.6 or later (for the 16.0 branch) or 16.1.1 or later (for the 16.1 branch). The fix addresses the improper authorization that allowed unauthenticated access to import error information.
Weakness (CWE)
CWE-209
EPSS Score
0.55%
Probability of exploitation in next 30 days
44.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.