CVE-2023-2233: Missing Authorization in GitLab
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2233?
CVE-2023-2233 is an improper authorization issue discovered in GitLab CE/EE affecting certain versions.
What is the severity of CVE-2023-2233?
The severity of CVE-2023-2233 is medium with a CVSS score of 4.3.
How does CVE-2023-2233 affect GitLab CE/EE?
CVE-2023-2233 allows a project reporter to leak the owner's Sentry instance projects in certain versions of GitLab CE/EE.
Which versions of GitLab CE/EE are affected by CVE-2023-2233?
CVE-2023-2233 affects all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1 of GitLab CE/EE.
How can I fix CVE-2023-2233?
To fix CVE-2023-2233, it is recommended to upgrade GitLab CE/EE to version 16.2.8, 16.3.5, or 16.4.1 or later.