CVE-2023-2478
08.05.2023, 21:15
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 15.4.0 ≤ 𝑥 < 15.9.7 |
gitlab | gitlab | 15.4.0 ≤ 𝑥 < 15.9.7 |
gitlab | gitlab | 15.10.0 ≤ 𝑥 < 15.10.6 |
gitlab | gitlab | 15.10.0 ≤ 𝑥 < 15.10.6 |
gitlab | gitlab | 15.11.0 ≤ 𝑥 < 15.11.2 |
gitlab | gitlab | 15.11.0 ≤ 𝑥 < 15.11.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References