Back

MEDIUM

Authorization Bypass Through User-Controlled Key in GitLab

Published Jul 13, 2023

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.1.1, 16.0.6, 15.11.10 or above.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jul 13, 2023
Updated Oct 30, 2024
Reserved Apr 19, 2023
CISA Vulnrichment
Updated Oct 30, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a