CVE Vulnerabilities

CVE-2023-3920

Insufficient Verification of Data Authenticity

Published: Sep 29, 2023 | Modified: Oct 03, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.2 (including) 16.2.8 (excluding)
Gitlab Gitlab 16.3.0 (including) 16.3.5 (excluding)
Gitlab Gitlab 16.4.0 (including) 16.4.0 (including)

References