CVE-2023-5106: Incorrect Authorization in GitLab
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5106?
The severity of CVE-2023-5106 is high with a CVSS score of 7.5.
Which versions of GitLab EE are affected by CVE-2023-5106?
All versions of GitLab EE starting from 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 are affected by CVE-2023-5106.
What is the impact of CVE-2023-5106?
CVE-2023-5106 could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
How can I fix CVE-2023-5106?
To fix CVE-2023-5106, update GitLab EE to version 16.2.8, 16.3.5, or 16.4.1 or later.
Where can I find more information about CVE-2023-5106?
You can find more information about CVE-2023-5106 in the GitLab commit mentioned in the reference: https://gitlab.com/gitlab-org/gitlab/-/commit/67039cfcae80b8fc0496f79be88714873cd169b3