High severity8.2NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-3932
CVE-2023-3932
Description
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.12
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.12.0,<16.0.8
- Range: starting from 13.12 before 16.0.8, starting from 16.1 before 16.1.3, starting from 16.2 before 16.2.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/417594nvdExploit
- hackerone.com/reports/2057633nvdPermissions Required
News mentions
2- GitLab Critical Security Release: 16.3.4 and 16.2.7GitLab Security Releases · Sep 18, 2023
- GitLab Security Release: 16.2.2, 16.1.3, and 16.0.8GitLab Security Releases · Aug 1, 2023