CVE-2023-5207: Execution with Unnecessary Privileges in GitLab
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE and EEto a version that resolves this vulnerability.Fixed in 16.4.1 - Upgrade
Upgrade
GitLab CE and EEto a version that resolves this vulnerability.Fixed in 16.3.5 - Upgrade
Upgrade
GitLab CE and EEto a version that resolves this vulnerability.Fixed in 16.2.8
Event History
Frequently Asked Questions
What is the vulnerability ID for this GitLab vulnerability?
The vulnerability ID for this GitLab vulnerability is CVE-2023-5207.
What is the severity of CVE-2023-5207?
The severity of CVE-2023-5207 is high with a CVSS score of 8.2.
Which versions of GitLab are affected by CVE-2023-5207?
All versions of GitLab starting from 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 are affected by CVE-2023-5207.
What can an authenticated attacker do with CVE-2023-5207?
An authenticated attacker can perform arbitrary pipeline execution under the context of another user with CVE-2023-5207.
Where can I find more information about CVE-2023-5207 vulnerability?
You can find more information about CVE-2023-5207 vulnerability at the following references: [Reference 1](https://gitlab.com/gitlab-org/gitlab/-/issues/425604), [Reference 2](https://gitlab.com/gitlab-org/gitlab/-/issues/425857), [Reference 3](https://hackerone.com/reports/2174141).