CVE-2023-5106Incorrect Authorization in Gitlab

Severity
7.5HIGHNVD
EPSS
0.0%
top 87.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2

Description

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.4.016.4.1
NVDgitlab/gitlab13.1216.2.8+2
debiandebian/gitlab
gitlabgitlab/gitlab

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-5106: An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 132023-10-02
GHSA
GHSA-chxc-x49q-7m83: An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 132023-10-02

📋Vendor Advisories

2
GitLab
CVE-2023-5106: An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.02023-10-02
Debian
CVE-2023-5106: gitlab - An issue has been discovered in Ultimate-licensed GitLab EE affecting all versio...2023