CVE-2023-3949

MEDIUM

GitLab <16.4.3-16.5.3-16.6.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for unauthorized users to view a public projects' release descriptions via an atom endpoint when release access on the public was set to only project members.

References (2)

Core 2
Core References
Broken Link, Vendor Advisory issue-tracking
https://gitlab.com/gitlab-org/gitlab/-/issues/419664
Permissions Required, Third Party Advisory technical-description exploit permissions-required
https://hackerone.com/reports/2079374

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (2)
gitlab/gitlab 16.6.0 (2 CPE variants)
gitlab/gitlab 11.3.0 - 16.4.3 (2 CPE variants)
Published Dec 01, 2023
Tracked Since Feb 18, 2026