High severity8.2NVD Advisory· Published Sep 19, 2023· Updated Jun 17, 2026
CVE-2023-5009
CVE-2023-5009
Description
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of CVE-2023-3932 showing additional impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.12
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.12,<16.2.7
- Range: from 13.12 before 16.2.7, from 16.3 before 16.3.4
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/425304nvdBroken Link
- hackerone.com/reports/2147126nvdPermissions Required
News mentions
1- GitLab Critical Security Release: 16.3.4 and 16.2.7GitLab Security Releases · Sep 18, 2023