Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2023-4630
Disclosure Date: September 11, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.
0
Attacker Value
Unknown
CVE-2023-4647
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
0
Attacker Value
Unknown
CVE-2023-4378
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.
0
Attacker Value
Unknown
CVE-2023-4018
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.
0
Attacker Value
Unknown
CVE-2023-3950
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
0
Attacker Value
Unknown
CVE-2023-3915
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.
0
Attacker Value
Unknown
CVE-2023-3210
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.
0
Attacker Value
Unknown
CVE-2023-3205
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.
0
Attacker Value
Unknown
CVE-2023-1555
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.
0
Attacker Value
Unknown
CVE-2023-1279
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.
0