CVE-2023-2190: Authorization Bypass Through User-Controlled Key in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2190?
The severity of CVE-2023-2190 is medium.
What is the affected software for CVE-2023-2190?
The affected software for CVE-2023-2190 is GitLab CE/EE versions 13.10 before 15.11.10, 16.0 before 16.0.6, and 16.1 before 16.1.1.
How can users view new commits to private projects in GitLab?
Users can view new commits to private projects in GitLab by creating a fork while the project was public and then setting it as private.
What is the Common Weakness Enumeration (CWE) for CVE-2023-2190?
The Common Weakness Enumeration (CWE) for CVE-2023-2190 is 639.
Where can I find more information about CVE-2023-2190?
You can find more information about CVE-2023-2190 at the following references: [HackerOne report](https://hackerone.com/reports/1944500) and [GitLab issue](https://gitlab.com/gitlab-org/gitlab/-/issues/408137).