VulnerabilityModified
CVE-2023-5207
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1.
HIGH 8.8EPSS 1.09%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-250
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/425604Broken Link
- https://gitlab.com/gitlab-org/gitlab/-/issues/425857Broken Link
- https://hackerone.com/reports/2174141Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/425604Broken Link
- https://gitlab.com/gitlab-org/gitlab/-/issues/425857Broken Link
- https://hackerone.com/reports/2174141Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.