VYPR
Medium severity5.4NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026

CVE-2023-3914

CVE-2023-3914

Description

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • GitLab Inc./GitLabv54 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.2.8
    • cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
    • (no CPE)range: <16.2.8, <16.3.5, <16.4.1
  • Range: <16.2.8, <16.3.5, <16.4.1
  • osv-coords
    Range: < 16.2.8

Patches

Vulnerability mechanics

References

2

News mentions

1