An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Oct 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Thu, 03 Oct 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Improper Access Control in GitLab | Direct Request ('Forced Browsing') in GitLab |
Weaknesses | CWE-425 |
Wed, 18 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2023-09-01T10:30:41.985Z
Updated: 2024-10-03T06:23:14.165Z
Reserved: 2023-07-31T12:30:31.240Z
Link: CVE-2023-4018
Vulnrichment
Updated: 2024-08-02T07:17:11.580Z
NVD
Status : Modified
Published: 2023-09-01T11:15:43.037
Modified: 2024-11-21T08:34:14.333
Link: CVE-2023-4018
Redhat
No data.