CRITICAL

CVE-2023-4008

Gitlab GitLab 2023-08-03 CVSS v3.1
CVSS
9.8

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

Summary dbcve.org

A vulnerability in GitLab Pages allows attackers to take over GitLab Pages sites that use unique domain URLs (e.g., project-name-abc123.example.com) if the attacker can determine the random string appended to the domain. The random string that was supposed to provide isolation between projects was predictable or discoverable.

Mitigation

Upgrade GitLab to version 16.0.8, 16.1.3, 16.2.2 or later. Alternatively, ensure proper network segmentation and monitor for unauthorized Pages domain registrations.

Weakness (CWE)

CWE-708

EPSS Score

0.71%
Probability of exploitation in next 30 days
51.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE