An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.
History

Thu, 03 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367

Thu, 03 Oct 2024 06:30:00 +0000

Type Values Removed Values Added
Title Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab Incorrect Ownership Assignment in GitLab
Weaknesses CWE-708

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2023-08-03T06:31:21.677Z

Updated: 2024-10-03T06:23:13.999Z

Reserved: 2023-07-31T07:13:53.508Z

Link: CVE-2023-4008

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:10.997Z

cve-icon NVD

Status : Modified

Published: 2023-08-03T07:15:13.190

Modified: 2024-11-21T08:34:13.093

Link: CVE-2023-4008

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-08-03T00:00:00Z

Links: CVE-2023-4008 - Bugzilla