Medium severity6.5NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2023-3915
CVE-2023-3915
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.1.0,<16.1.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.1.0,<16.1.5
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
- (no CPE)range: starting from 16.1 before 16.1.5, starting from 16.2 before 16.2.5, starting from 16.3 before 16.3.1
- Range: starting from 16.1 before 16.1.5, starting from 16.2 before 16.2.5, starting from 16.3 before 16.3.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/417664nvdBroken Link
- hackerone.com/reports/2040834nvdPermissions Required
News mentions
1- GitLab Security Release: 16.3.1, 16.2.5, and 16.1.5GitLab Security Releases · Aug 31, 2023