An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/419857 Broken Link Vendor Advisory
https://hackerone.com/reports/2037316 Permissions Required Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2023-12-01T07:02:18.158Z

Updated: 2023-12-01T07:02:18.158Z

Reserved: 2023-07-26T22:30:27.029Z


Link: CVE-2023-3964

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-01T07:15:09.620

Modified: 2023-12-06T18:32:45.550


Link: CVE-2023-3964

JSON object: View

cve-icon Redhat Information

No data.