HIGH
CVE-2023-3993
CVSS
7.5
Description
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.
Summary dbcve.org
In GitLab EE versions 14.3 through 16.2.2, access tokens may be logged in plaintext when queries are made to a specific endpoint, resulting in information disclosure of sensitive authentication credentials.
Mitigation
Upgrade GitLab EE to version 16.0.8+, 16.1.3+, or 16.2.2+ as appropriate. Audit existing logs for exposed tokens and rotate any potentially compromised access tokens as a precaution.
Weakness (CWE)
CWE-532
Sensitive Information in Logs
EPSS Score
0.72%
Probability of exploitation in next 30 days
52.6th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.