CVE-2023-3949
Description
An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.
Summary dbcve.org
GitLab had an authorization bypass where the atom endpoint (used for RSS/Atom feeds) failed to enforce release access controls, allowing unauthorized users to view release descriptions in public projects even when release visibility was configured to restrict access to project members only.
Mitigation
Upgrade GitLab to version 16.4.3, 16.5.3, 16.6.1 or later to patch the authorization bypass in the atom endpoint.