MEDIUM

CVE-2023-3914

Gitlab GitLab 2023-09-29 CVSS v3.1
CVSS
5.3

Description

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

Summary dbcve.org

A business logic error in GitLab EE allows access to internal projects because service accounts are not deleted when their associated namespace is deleted. This leaves orphaned service accounts that retain access to internal projects that should no longer be accessible.

Mitigation

Upgrade to GitLab 16.2.8, 16.3.5, or 16.4.1 or later. Additionally, audit for and manually remove orphaned service accounts associated with deleted namespaces to ensure internal project access is properly revoked.

Weakness (CWE)

CWE-286

EPSS Score

0.37%
Probability of exploitation in next 30 days
30.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE