MEDIUM

CVE-2023-4002

Gitlab GitLab 2023-08-04 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab EE where users with EE licenses could link any security policy project by its ID to projects or groups they have access to, without proper authorization checks. This allows unauthorized users to potentially view security policies configured in protected security policy projects.

Mitigation

Upgrade GitLab EE to versions 16.0.8, 16.1.3, or 16.2.2 or later. Until upgraded, monitor access to security policy project linkages and restrict knowledge of security policy project IDs to authorized personnel only.

Weakness (CWE)

CWE-201

EPSS Score

0.59%
Probability of exploitation in next 30 days
46.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE