First published: Wed May 03 2023(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.0<12.9.8 | |
GitLab | >=12.10.0<12.10.7 | |
GitLab | >=13.0<13.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2069 is considered a high severity vulnerability due to the potential leakage of sensitive CI/CD variables.
CVE-2023-2069 affects GitLab versions from 10.0 to before 12.9.8, 12.10 from 12.10.0 to before 12.10.7, and 13.0 before 13.0.1.
To fix CVE-2023-2069, upgrade GitLab to version 12.9.8 or later, 12.10.7 or later, or 13.0.1 or later.
The impact of CVE-2023-2069 allows a developer role user to exploit the import project feature to disclose CI/CD variables.
CVE-2023-2069 was discovered through security research and reported by the GitLab community.