Description
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 16.2.5 or 16.3.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44576 | An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it. |
References
History
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-20T04:09:08.266Z
Reserved: 2023-07-25T17:30:22.877Z
Link: CVE-2023-3950
Updated: 2024-08-02T07:08:50.670Z
Status : Modified
Published: 2023-09-01T11:15:42.457
Modified: 2024-11-21T08:18:23.267
Link: CVE-2023-3950
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD