HIGH

CVE-2023-5207

Gitlab GitLab 2023-09-30 CVSS v3.1
CVSS
8.8

Description

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

Summary dbcve.org

An authenticated attacker can execute arbitrary CI/CD pipelines under the context of another GitLab user, enabling privilege escalation and unauthorized access to resources accessible via pipeline execution.

Mitigation

Upgrade GitLab to version 16.2.8, 16.3.5, 16.4.1 or later to patch the arbitrary pipeline execution vulnerability.

Weakness (CWE)

CWE-250

EPSS Score

1.09%
Probability of exploitation in next 30 days
64th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE