VYPR
Medium severity5.5NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026

CVE-2023-3950

CVE-2023-3950

Description

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • GitLab Inc./GitLabv55 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.2
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.2,<16.2.5
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.2,<16.2.5
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
  • Range: 16.2 <= versions < 16.2.5, 16.3 < versions < 16.3.1
  • osv-coords
    Range: >= 16.2.0, < 16.2.5

Patches

Vulnerability mechanics

References

2

News mentions

1