CVE-2023-0120: Incorrect Authorization in GitLab
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0120?
CVE-2023-0120 is an issue that has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, and all versions starting from 16.3 before 16.3.1.
What is the severity of CVE-2023-0120?
CVE-2023-0120 has a severity score of 4.3, which is considered medium.
How does CVE-2023-0120 impact GitLab?
CVE-2023-0120 allows unauthorised users to edit labels description due to improper permission validation.
Which software versions are affected by CVE-2023-0120?
CVE-2023-0120 affects GitLab versions starting from 10.0 before 16.1.5, versions starting from 16.2 before 16.2.5, and versions starting from 16.3 before 16.3.1.
Are there any references related to CVE-2023-0120?
Yes, you can find more information about CVE-2023-0120 in the following references: [GitLab issue](https://gitlab.com/gitlab-org/gitlab/-/issues/387531) and [HackerOne report](https://hackerone.com/reports/1818425).