CVE Vulnerabilities

CVE-2023-3950

Cleartext Storage of Sensitive Information

Published: Sep 01, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.8
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.2 (including) 16.2.5 (excluding)
Gitlab Gitlab 16.3.0 (including) 16.3.0 (including)

Potential Mitigations

References