An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2023-09-01T10:30:46.990Z
Updated: 2024-09-18T04:06:20.213Z
Reserved: 2023-07-25T17:30:22.877Z
Link: CVE-2023-3950
Vulnrichment
Updated: 2024-08-02T07:08:50.670Z
NVD
Status : Modified
Published: 2023-09-01T11:15:42.457
Modified: 2024-11-21T08:18:23.267
Link: CVE-2023-3950
Redhat
No data.