MEDIUM
CVE-2023-3914
CVSS
5.3
Description
A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
Summary dbcve.org
A business logic error in GitLab EE allows access to internal projects because service accounts are not deleted when their associated namespace is deleted. This leaves orphaned service accounts that retain access to internal projects that should no longer be accessible.
Mitigation
Upgrade to GitLab 16.2.8, 16.3.5, or 16.4.1 or later. Additionally, audit for and manually remove orphaned service accounts associated with deleted namespaces to ensure internal project access is properly revoked.
Weakness (CWE)
CWE-286
EPSS Score
0.37%
Probability of exploitation in next 30 days
30.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.