MEDIUM

CVE-2023-3362

Gitlab GitLab 2023-07-13 CVSS v3.1
CVSS
5.3

Description

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

Summary dbcve.org

GitLab CE/EE versions 16.0 through 16.0.5 and 16.1.0 contain an information disclosure vulnerability where unauthenticated users can access import error details for projects that were imported from GitHub. This occurs due to improper access controls on the import error reporting functionality.

Mitigation

Upgrade GitLab to version 16.0.6 or later (for the 16.0 branch) or 16.1.1 or later (for the 16.1 branch). The fix addresses the improper authorization that allowed unauthenticated access to import error information.

Weakness (CWE)

CWE-209

EPSS Score

0.55%
Probability of exploitation in next 30 days
44.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE