High severity8.0NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2023-3484
CVE-2023-3484
Description
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.8.0,<15.11.11
- (no CPE)range: 12.8 <= v < 15.11.11, 16.0 <= v < 16.0.7, 16.1 <= v < 16.1.2
- Range: 12.8 <= v < 15.11.11, 16.0 <= v < 16.0.7, 16.1 <= v < 16.1.2
Patches
Vulnerability mechanics
References
3- about.gitlab.com/releases/2023/07/05/security-release-gitlab-16-1-2-released/nvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/416773nvdBroken Link
- hackerone.com/reports/2035687nvdPermissions Required
News mentions
1- GitLab Security Release: 16.1.2, 16.0.7, and 15.11.11GitLab Security Releases · Jul 5, 2023