CVE Vulnerabilities

CVE-2023-0989

Improper Ownership Management

Published: Sep 29, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

Weakness

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.11 (including) 16.2.8 (excluding)
Gitlab Gitlab 16.3.0 (including) 16.3.5 (excluding)
Gitlab Gitlab 16.4.0 (including) 16.4.0 (including)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *

Potential Mitigations

References