CVE-2023-3950
01.09.2023, 11:15
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 16.2 ≤ 𝑥 < 16.2.5 |
gitlab | gitlab | 16.2 ≤ 𝑥 < 16.2.5 |
gitlab | gitlab | 16.3.0 |
gitlab | gitlab | 16.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration