5.3
CVSSv3

CVE-2023-3914

Published: 29/09/2023 Updated: 03/10/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A business logic error in GitLab EE affecting all versions before 16.2.8, 16.3 before 16.3.5, and 16.4 before 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 16.4.0