CWE
863
Advisory Published
Updated

CVE-2023-3509: Incorrect Authorization in GitLab

First published: Wed Feb 21 2024(Updated: )

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

Credit: cve@gitlab.com

Affected SoftwareAffected VersionHow to fix
GitLab<=16.7.6
GitLab>=16.8.0<=16.8.3
GitLab=16.9.0

Remedy

Upgrade to versions 16.9.1, 16.8.3, 16.7.6 or above.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What versions are affected by CVE-2023-3509?

    CVE-2023-3509 affects GitLab versions before 16.7.6, 16.8.0 to 16.8.2, and specifically 16.9.0.

  • What is the impact of CVE-2023-3509?

    CVE-2023-3509 allows group members with sub-maintainer roles to change the title of privately accessible deploy keys.

  • How do I fix CVE-2023-3509?

    To mitigate CVE-2023-3509, upgrade your GitLab instance to version 16.7.6 or apply the fixes in versions 16.8.3 and 16.9.1 or later.

  • Is CVE-2023-3509 a critical vulnerability?

    CVE-2023-3509 is considered a moderate risk as it could lead to unauthorized changes to sensitive deploy keys.

  • Who can exploit CVE-2023-3509?

    CVE-2023-3509 can be exploited by group members who have been assigned the sub-maintainer role.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203