CVE-2023-1710Sensitive Information Exposure in Gitlab

Severity
5.3MEDIUMNVD
EPSS
2.7%
top 14.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5

Description

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDgitlab/gitlab15.0.015.8.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=15.0, <15.8.5, >=15.10, <15.10.1, >=15.9, <15.9.4+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-qwxw-v6wx-qh2q: A sensitive information disclosure vulnerability in GitLab affecting all versions from 152023-04-05
OSV
CVE-2023-1710: A sensitive information disclosure vulnerability in GitLab affecting all versions from 152023-04-05

📋Vendor Advisories

2
GitLab
CVE-2023-1710: A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 12023-04-05
Debian
CVE-2023-1710: gitlab - A sensitive information disclosure vulnerability in GitLab affecting all version...2023