MEDIUM

CVE-2023-3949

Gitlab GitLab 2023-12-01 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

Summary dbcve.org

GitLab had an authorization bypass where the atom endpoint (used for RSS/Atom feeds) failed to enforce release access controls, allowing unauthorized users to view release descriptions in public projects even when release visibility was configured to restrict access to project members only.

Mitigation

Upgrade GitLab to version 16.4.3, 16.5.3, 16.6.1 or later to patch the authorization bypass in the atom endpoint.

Weakness (CWE)

CWE-201

EPSS Score

0.59%
Probability of exploitation in next 30 days
47th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE