MEDIUM

CVE-2023-4018

Gitlab GitLab 2023-09-01 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

Summary dbcve.org

GitLab versions 16.2 through 16.2.5 and 16.3 through 16.3.1 contain an improper permission validation vulnerability in the model experiments feature. Due to inadequate access control checks, authenticated users could create model experiments in public projects even without proper authorization, potentially allowing unauthorized modification of project resources.

Mitigation

Upgrade GitLab to version 16.2.5 or 16.3.1 or later to resolve the improper permission validation issue.

Weakness (CWE)

CWE-425

EPSS Score

0.46%
Probability of exploitation in next 30 days
39.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE