CVE-2023-5061: Developer can bypass predefined variables via REST API
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5061?
CVE-2023-5061 has been classified with a medium severity rating due to its potential impact on GitLab CI variable settings.
How do I fix CVE-2023-5061?
To mitigate CVE-2023-5061, upgrade GitLab to version 16.4.4 or later, or to versions 16.5.4 or later, or 16.6.2 or later.
Which versions of GitLab are affected by CVE-2023-5061?
CVE-2023-5061 affects all GitLab versions from 9.3 to prior to 16.4.4, 16.5 to prior to 16.5.4, and 16.6 to prior to 16.6.2.
What potential impact does CVE-2023-5061 have on GitLab users?
CVE-2023-5061 may allow developers to override predefined CI variables, which could lead to unwanted changes in CI/CD pipelines.
Is there a workaround for CVE-2023-5061 if I cannot update GitLab immediately?
Currently, there are no documented workarounds for CVE-2023-5061, so it is recommended to update GitLab as soon as possible.