Skip to content

CVE-2023-3484 | GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations..This CVE has a CVSS3.1 score of 8 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-3484
CVE StatePUBLISHED
BaseScore8
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
VersionNA

References for CVE-2023-3484 :
https://gitlab.com/gitlab-org/gitlab/-/issues/416773
https://hackerone.com/reports/2035687

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)HIGH
PrivilegesRequired(PR)LOW
UserInteraction(UI)REQUIRED
Scope(S)CHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH
Tags: