CVE-2023-1710: Infoleak
Published Apr 5, 2023
·Updated
A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to 15.10.1 allows an attacker to view the count of internal notes for a given issue.
Affected Software
6 affected components
GitLab GitLab>=15.0.0<15.8.5
GitLab GitLab>=15.0.0<15.8.5
GitLab GitLab>=15.9.0<15.9.4
GitLab GitLab>=15.9.0<15.9.4
GitLab GitLab=15.10.0
GitLab GitLab=15.10.0
Event History
Apr 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-1710?
CVE-2023-1710 is a sensitive information disclosure vulnerability in GitLab that allows an attacker to view the count of internal notes for a given issue.
2
Which versions of GitLab are affected by CVE-2023-1710?
All versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 are affected.
3
What is the severity of CVE-2023-1710?
The severity of CVE-2023-1710 is medium (5.3).
4
How can I fix CVE-2023-1710 in GitLab?
To fix CVE-2023-1710, update GitLab to version 15.8.5, 15.9.4, or 15.10.1 or later.
5
Where can I find more information about CVE-2023-1710?
You can find more information about CVE-2023-1710 on the GitLab official CVE page and the GitLab issue tracker.