First published: Wed Apr 05 2023(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.9.0<15.9.4 | |
GitLab | >=15.9.0<15.9.4 | |
GitLab | =15.10.0 | |
GitLab | =15.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1417 has been classified as a moderate severity vulnerability.
To mitigate CVE-2023-1417, update GitLab to version 15.9.4 or 15.10.1 or later.
CVE-2023-1417 affects all GitLab versions starting from 15.9 before 15.9.4 and all versions starting from 15.10 before 15.10.1.
CVE-2023-1417 describes a vulnerability that allows unauthorized users to add child epics to a victim's epic in unrelated groups.
CVE-2023-1417 was discovered and reported in early 2023.