HIGH

CVE-2023-3399

Gitlab GitLab 2023-11-06 CVSS v3.1
CVSS
7.7

Description

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab EE where an unauthorized project or group member could read CI/CD variables through custom project templates. The vulnerability allows exposure of sensitive environment variables that typically contain secrets, API tokens, and credentials used in CI/CD pipelines.

Mitigation

Upgrade GitLab EE to versions 16.3.6, 16.4.2, 16.5.1 or later. Additionally, audit CI/CD variables to rotate any potentially exposed secrets and review member permissions on projects using custom templates.

Weakness (CWE)

CWE-201

EPSS Score

0.45%
Probability of exploitation in next 30 days
38.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE