Skip to content

CVE-2023-3102 | GitLab

A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR..This CVE has a CVSS3.1 score of 5.3 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-3102
CVE StatePUBLISHED
BaseScore5.3
BaseSeverityMEDIUM
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
VersionNA

References for CVE-2023-3102 :
https://gitlab.com/gitlab-org/gitlab/-/issues/414269
https://hackerone.com/reports/2012073

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)NONE
Integrity(I)NONE