CVE-2023-4008
MEDIUMGitLab CE/EE <16.0.8-16.2.2 - Info Disclosure
Title source: llmDescription
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.
Scores
CVSS v3
5.3
EPSS
0.0005
EPSS Percentile
16.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-708
Status
published
Affected Products (2)
gitlab/gitlab
< 16.0.8
gitlab/gitlab
< 16.0.8
Timeline
Published
Aug 03, 2023
Tracked Since
Feb 18, 2026