HIGH🇵🇱 Wersja polska

CVE-2023-3932

CVSS 8.2v3.1pub. 2023-08-03upd. 2024-11-21

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
  • GitLab

    APP
    Gitlab
    13.12.0 – 16.0.8 (excl.)16.1.0 – 16.1.3 (excl.)16.2.0 – 16.2.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
CI/CD
CWE
References

Related vulnerabilities

CVE-2023-7028CRITICAL10.0⚠ KEVPL ✓same product

GitLab: Przejęcie konta przez reset hasła na niezweryfikowany e-mail

CVE-2021-22205CRITICAL10.0⚠ KEVPL ✓same product

RCE w GitLab CE/EE poprzez nieprawidłową walidację plików obrazów

CVE-2026-19478CRITICAL9.4same product

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 1...

CVE-2024-7102CRITICAL9.6PL ✓same product

GitLab CE/EE: uruchomienie pipeline jako inny użytkownik (privilege escalation)

CVE-2024-9164CRITICAL9.6PL ✓same product

GitLab EE: uruchamianie pipeline CI/CD na dowolnych gałęziach bez autoryzacji