CVE-2023-4630 Information
Sep 16, 2023
cve
Description
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5 all versions starting from 16.2 before 16.2.5 all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project’s imports.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://gitlab.com/gitlab-org/gitlab/-/issues/415117 https://about.gitlab.com/releases/2023/08/31/security-release-gitlab-16-3-1-released/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: