CVE-2023-0483: Medium severity gitlab vulnerability
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0483?
CVE-2023-0483 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive API keys.
How do I fix CVE-2023-0483?
To mitigate CVE-2023-0483, update GitLab to the latest version beyond 15.7.8, 15.8.4, or 15.9.2 as applicable.
Who is affected by CVE-2023-0483?
CVE-2023-0483 affects all GitLab versions starting from 12.1 to just before 15.7.8, 15.8 to just before 15.8.4, and 15.9 to just before 15.9.2.
What impact does CVE-2023-0483 have on GitLab users?
If exploited, CVE-2023-0483 allows a project maintainer to extract sensitive Datadog integration API keys, potentially compromising services.
When was CVE-2023-0483 discovered?
CVE-2023-0483 was recently discovered and affects multiple versions of GitLab before the specified patch releases.