Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0485


An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork.


Published

2023-05-03T21:15:16.577

Last Modified

2024-11-21T07:37:16.357

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-668

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.8.5 Yes
Application gitlab gitlab < 15.9.4 Yes
Application gitlab gitlab < 15.11.1 Yes

References