VYPR
Low severity2.7NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026

CVE-2023-1555

CVE-2023-1555

Description

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.

Affected products

7
  • GitLab Inc./GitLabllm-fuzzy6 versions
    from 15.2 before 16.1.5, from 16.2 before 16.2.5, from 16.3 before 16.3.1+ 5 more
    • (no CPE)range: from 15.2 before 16.1.5, from 16.2 before 16.2.5, from 16.3 before 16.3.1
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.2
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.2.0,<16.1.5
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.2.0,<16.1.5
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
  • osv-coords
    Range: >= 15.2.0, < 16.1.5

Patches

Vulnerability mechanics

References

2

News mentions

1