CVE-2023-5009: Incorrect Authorization in GitLab
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of CVE-2023-3932 showing additional impact.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-5009?
CVE-2023-5009 is a vulnerability discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7.
What is the severity of CVE-2023-5009?
CVE-2023-5009 has a severity rating of 9.6, which is classified as critical.
How does CVE-2023-5009 impact GitLab EE?
CVE-2023-5009 allows an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.
How can I check if my GitLab EE version is affected by CVE-2023-5009?
If your GitLab EE version is between 13.12 and 16.2.7, or between 16.3 and 16.3.4, it is affected by CVE-2023-5009.
How can I mitigate CVE-2023-5009 in GitLab EE?
To mitigate CVE-2023-5009, you should update to GitLab EE version 16.2.7 or higher, or version 16.3.4 or higher.