CVE-2023-4008
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.
Summary dbcve.org
A vulnerability in GitLab Pages allows attackers to take over GitLab Pages sites that use unique domain URLs (e.g., project-name-abc123.example.com) if the attacker can determine the random string appended to the domain. The random string that was supposed to provide isolation between projects was predictable or discoverable.
Mitigation
Upgrade GitLab to version 16.0.8, 16.1.3, 16.2.2 or later. Alternatively, ensure proper network segmentation and monitor for unauthorized Pages domain registrations.