5.3

CVE-2023-3914

Incorrect User Management in GitLab

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition enterprise Version < 16.2.8
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.3.0 < 16.3.5
Gitlab ≫ GitLab Version 16.4.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cve@gitlab.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-286 Incorrect User Management

The product does not properly manage a user within its environment.

https://gitlab.com/gitlab-org/gitlab/-/issues/418115
Broken Link
https://hackerone.com/reports/2040822
Permissions Required