A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2023-09-29T06:02:21.304Z

Updated: 2023-09-29T06:02:21.304Z

Reserved: 2023-07-25T10:30:31.597Z


Link: CVE-2023-3914

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-29T07:15:13.380

Modified: 2023-10-03T15:31:20.073


Link: CVE-2023-3914

JSON object: View

cve-icon Redhat Information

No data.