Medium severity5.5NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2023-3950
CVE-2023-3950
Description
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.2,<16.2.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.2,<16.2.5
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
- Range: 16.2 <= versions < 16.2.5, 16.3 < versions < 16.3.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/419675nvdBroken Link
- hackerone.com/reports/2079154nvdPermissions Required
News mentions
1- GitLab Security Release: 16.3.1, 16.2.5, and 16.1.5GitLab Security Releases · Aug 31, 2023