Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-3915— Incorrect Execution-Assigned Permissions in GitLab

CVSS 6.5 · Medium EPSS 0.56% · P44

Possible ATT&CK Techniques 1AI

T1078 · Valid Accounts

Affected Version Matrix 3

VendorProductVersion RangeStatus
GitLabGitLab16.1< 16.1.5affected
16.2< 16.2.5affected
16.3< 16.3.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-3915

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect Execution-Assigned Permissions in GitLab
Source: CVE Program / CVE List V5
Vulnerability Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不安全的运行时授予权限
Source: CVE Program / CVE List V5
Vulnerability Title
GitLab 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 GitLab 存在安全漏洞,该漏洞源于如果外部用户被授予任何组的所有者角色,则该外部用户可以通过在该组中创建服务帐户来升级其在实例上的权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
GitLabGitLab 16.1 ~ 16.1.5 cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2023-3915

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-3915

登录查看更多情报信息。

Other References for CVE-2023-3915 (2)

Same Patch Batch · GitLab · 2023-09-01 · 11 CVEs total

CVE-2023-32106.5 MEDIUMInefficient Regular Expression Complexity in GitLab
CVE-2023-32056.5 MEDIUMInefficient Regular Expression Complexity in GitLab
CVE-2023-39505.5 MEDIUMCleartext Storage of Sensitive Information in GitLab
CVE-2023-43785.5 MEDIUMInsertion of Sensitive Information Into Sent Data in GitLab
CVE-2023-46475.3 MEDIUMAllocation of Resources Without Limits or Throttling in GitLab
CVE-2022-43435.0 MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLab
CVE-2023-40184.3 MEDIUMDirect Request ('Forced Browsing') in GitLab
CVE-2023-01203.5 LOWIncorrect Authorization in GitLab
CVE-2023-15552.7 LOWMissing Authorization in GitLab
CVE-2023-12792.6 LOWURL Redirection to Untrusted Site in GitLab

IV. Related Vulnerabilities

V. Comments for CVE-2023-3915

No comments yet


Leave a comment