Back

MEDIUM

Incorrect Authorization in GitLab

Published Sep 29, 2023

Description

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.4.1, 16.3.5, 16.2.8 or above.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitLab
Published Sep 29, 2023
Updated Apr 26, 2026
Reserved Aug 25, 2023

CISA Vulnrichment

Updated Jul 24, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitLab
Published Sep 29, 2023
Updated Apr 26, 2026

GitHub

No data