First published: Thu Mar 09 2023(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.5.0<15.7.8 | |
GitLab | >=15.5.0<15.7.8 | |
GitLab | >=15.8.0<15.8.4 | |
GitLab | >=15.8.0<15.8.4 | |
GitLab | >=15.9.0<15.9.2 | |
GitLab | >=15.9.0<15.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0223 has been classified as a medium severity vulnerability.
To fix CVE-2023-0223, upgrade GitLab to version 15.7.8 or later, 15.8.4 or later, or 15.9.2 or later.
CVE-2023-0223 affects all versions of GitLab from 15.5 before 15.7.8, 15.8 before 15.8.4, and 15.9 before 15.9.2 for both community and enterprise editions.
CVE-2023-0223 allows non-project members to retrieve release descriptions via the API, compromising release visibility.
Versions of GitLab from 15.5.0 to before 15.7.8, from 15.8.0 to before 15.8.4, and from 15.9.0 to before 15.9.2 are vulnerable in CVE-2023-0223.