CVE-2023-3914

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*

History

03 Oct 2023, 15:31

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/418115 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/418115 - Broken Link
References (MISC) https://hackerone.com/reports/2040822 - (MISC) https://hackerone.com/reports/2040822 - Permissions Required
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Gitlab
Gitlab gitlab

29 Sep 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-29 07:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-3914

Mitre link : CVE-2023-3914

CVE.ORG link : CVE-2023-3914


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
NVD-CWE-Other CWE-840

Business Logic Errors