CVE-2023-2190

MEDIUM

GitLab CE/EE <15.11.10-16.0.6-16.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public.

References (2)

Core 2
Core References
Broken Link, Vendor Advisory issue-tracking
https://gitlab.com/gitlab-org/gitlab/-/issues/408137
Third Party Advisory technical-description exploit
https://hackerone.com/reports/1944500

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
gitlab/gitlab 13.10.0 - 15.11.10 (2 CPE variants)
Published Jul 13, 2023
Tracked Since Feb 18, 2026