Unrated severityNVD Advisory· Published Sep 29, 2023· Updated Nov 20, 2025
Missing Authorization in GitLab
CVE-2023-2233
Description
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.
Affected products
3- Range: >=11.8, <16.2.8; >=16.3, <16.3.5; >=16.4, <16.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/1947211mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/408359mitreissue-tracking
News mentions
1- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023