HIGH

CVE-2023-3993

Gitlab GitLab 2023-08-02 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. Access tokens may have been logged when a query was made to a specific endpoint.

Summary dbcve.org

In GitLab EE versions 14.3 through 16.2.2, access tokens may be logged in plaintext when queries are made to a specific endpoint, resulting in information disclosure of sensitive authentication credentials.

Mitigation

Upgrade GitLab EE to version 16.0.8+, 16.1.3+, or 16.2.2+ as appropriate. Audit existing logs for exposed tokens and rotate any potentially compromised access tokens as a precaution.

Weakness (CWE)

CWE-532 Sensitive Information in Logs

EPSS Score

0.72%
Probability of exploitation in next 30 days
52.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE