Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-3399
HistoryNov 06, 2023 - 12:00 a.m.

CVE-2023-3399

2023-11-0600:00:00
ubuntu.com
ubuntu.com
3
cve-2023-3399
gitlab ee
unix
security issue

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

AI Score

6.6

Confidence

Low

An issue has been discovered in GitLab EE affecting all versions starting
from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all
versions starting from 16.5 before 16.5.1. It was possible for an
unauthorised project or group member to read the CI/CD variables using the
custom project templates.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchgitlab< anyUNKNOWN
ubuntu24.04noarchgitlab-agent< anyUNKNOWN

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

AI Score

6.6

Confidence

Low