CVE-2023-1555: Missing Authorization in GitLab
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-1555?
CVE-2023-1555 is an issue discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.
What is the severity of CVE-2023-1555?
The severity of CVE-2023-1555 is medium with a CVSS score of 4.3.
What software versions are affected by CVE-2023-1555?
CVE-2023-1555 affects GitLab versions 15.2 to 16.1.5, 16.2 to 16.2.5, and 16.3 to 16.3.1.
How can a namespace-level banned user access the API?
A namespace-level banned user can access the API due to the vulnerability in GitLab.
Where can I find more information about CVE-2023-1555?
You can find more information about CVE-2023-1555 on the GitLab issue page (https://gitlab.com/gitlab-org/gitlab/-/issues/398587) and the HackerOne report (https://hackerone.com/reports/1911908).