Medium severity4.3NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-5061
CVE-2023-5061
Description
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 9.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=9.3.0,<16.4.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=9.3.0,<16.4.4
- (no CPE)range: >=9.3 <16.4.4, >=16.5 <16.5.4, >=16.6 <16.6.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/425521nvdBroken Link
- hackerone.com/reports/2125189nvdPermissions Required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023