CVE-2023-3399
Description
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab EE where an unauthorized project or group member could read CI/CD variables through custom project templates. The vulnerability allows exposure of sensitive environment variables that typically contain secrets, API tokens, and credentials used in CI/CD pipelines.
Mitigation
Upgrade GitLab EE to versions 16.3.6, 16.4.2, 16.5.1 or later. Additionally, audit CI/CD variables to rotate any potentially exposed secrets and review member permissions on projects using custom templates.