Low severity3.1NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026
CVE-2023-2233
CVE-2023-2233
Description
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 11.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.8,<16.2.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.8,<16.2.8
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=11.8 <16.2.8, >=16.3 <16.3.5, >=16.4 <16.4.1
- Range: >=11.8 <16.2.8, >=16.3 <16.3.5, >=16.4 <16.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/408359nvdBroken Link
- hackerone.com/reports/1947211nvdPermissions Required
News mentions
1- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023