VYPR
High severity8.5NVD Advisory· Published Nov 6, 2023· Updated Jun 17, 2026

CVE-2023-3399

CVE-2023-3399

Description

An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.

Affected products

7
  • GitLab Inc./GitLabv55 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 11.6
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.6.0,<12.9.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.6.0,<12.9.8
    • cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*
  • Range: starting from 11.6 before 16.3.6, starting from 16.4 before 16.4.2, starting from 16.5 before 16.5.1
  • osv-coords
    Range: >= 11.6.0, < 16.3.6

Patches

Vulnerability mechanics

References

2

News mentions

1