CVE-2023-1084: Low severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1084?
CVE-2023-1084 has been classified as a critical vulnerability due to its potential to allow project maintainers to create Project Access Tokens with owner-level privileges.
How do I fix CVE-2023-1084?
To address CVE-2023-1084, upgrade GitLab to version 15.7.8 or to a version 15.8.4 and above.
Which versions of GitLab are affected by CVE-2023-1084?
CVE-2023-1084 affects all versions of GitLab before 15.7.8, between 15.8.0 and before 15.8.4, and between 15.9.0 and before 15.9.2.
What type of access does a compromised Project Access Token provide in CVE-2023-1084?
A compromised Project Access Token allows full owner-level access, enabling malicious actions within the GitLab project.
Who can exploit the vulnerability described in CVE-2023-1084?
The vulnerability can be exploited by a malicious project maintainer who leverages a crafted request to create a privileged access token.