CVE-2023-2589: Medium severity gitlab vulnerability
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2589?
CVE-2023-2589 has been rated with high severity due to the potential for unauthorized access to GitLab repositories.
How do I fix CVE-2023-2589?
To remediate CVE-2023-2589, you should upgrade to GitLab version 15.10.8, 15.11.7, or 16.0.2 or later.
What versions are affected by CVE-2023-2589?
CVE-2023-2589 affects all GitLab versions starting from 12.0 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2.
What type of attack is possible with CVE-2023-2589?
An attacker can clone a repository from a public project from a disallowed IP address due to CVE-2023-2589.
Is my GitLab community version impacted by CVE-2023-2589?
Yes, the GitLab community version is impacted by CVE-2023-2589 if it is within the affected version range.