VulnerabilityModified
CVE-2023-1167
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.
MEDIUM 5.3EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862, CWE-285
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/392715Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/392715Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.