An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.
History

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2023-08-03T06:31:21.677Z

Updated: 2024-08-30T15:44:49.084Z

Reserved: 2023-07-31T07:13:53.508Z

Link: CVE-2023-4008

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:10.997Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-03T07:15:13.190

Modified: 2023-08-07T19:29:10.320

Link: CVE-2023-4008

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-08-03T00:00:00Z

Links: CVE-2023-4008 - Bugzilla