CVE-2023-1098: Medium severity gitlab vulnerability
An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1098?
CVE-2023-1098 has been classified as an information disclosure vulnerability affecting multiple versions of GitLab.
How do I fix CVE-2023-1098?
To fix CVE-2023-1098, upgrade your GitLab installation to version 15.8.5 or higher, 15.9.4 or higher, or 15.10.1 or higher.
Which versions of GitLab are affected by CVE-2023-1098?
CVE-2023-1098 affects all GitLab versions starting from 11.5 up to but not including 15.8.5, as well as specific ranges of 15.9 and 15.10 versions.
What kind of information is leaked by CVE-2023-1098?
CVE-2023-1098 allows an admin to leak passwords from a repository mirror configuration.
Who is primarily affected by CVE-2023-1098?
Admins of GitLab installations that are on the affected versions are primarily impacted by CVE-2023-1098.