CVE-2023-4002
Description
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab EE where users with EE licenses could link any security policy project by its ID to projects or groups they have access to, without proper authorization checks. This allows unauthorized users to potentially view security policies configured in protected security policy projects.
Mitigation
Upgrade GitLab EE to versions 16.0.8, 16.1.3, or 16.2.2 or later. Until upgraded, monitor access to security policy project linkages and restrict knowledge of security policy project IDs to authorized personnel only.