
CVE-2023-0319
https://notcve.org/view.php?id=CVE-2023-0319
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0319.json • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVE-2023-0523
https://notcve.org/view.php?id=CVE-2023-0523
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0523.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-0450
https://notcve.org/view.php?id=CVE-2023-0450
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0450.json •

CVE-2023-1787
https://notcve.org/view.php?id=CVE-2023-1787
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1787.json •

CVE-2023-1071
https://notcve.org/view.php?id=CVE-2023-1071
05 Apr 2023 — An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json • CWE-863: Incorrect Authorization •

CVE-2023-0838
https://notcve.org/view.php?id=CVE-2023-0838
05 Apr 2023 — An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0838.json • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2023-1167
https://notcve.org/view.php?id=CVE-2023-1167
05 Apr 2023 — Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1167.json • CWE-862: Missing Authorization •

CVE-2023-1733
https://notcve.org/view.php?id=CVE-2023-1733
05 Apr 2023 — A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1733.json •

CVE-2022-4331
https://notcve.org/view.php?id=CVE-2022-4331
09 Mar 2023 — An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4331.json • CWE-284: Improper Access Control •

CVE-2023-0050
https://notcve.org/view.php?id=CVE-2023-0050
09 Mar 2023 — An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims. • https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0050.json • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •