An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitLab
Published: 2023-10-02T11:49:56.333Z
Updated: 2023-10-02T11:49:56.333Z
Reserved: 2023-09-21T10:30:28.355Z
Link: CVE-2023-5106
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-02T12:15:09.997
Modified: 2023-10-04T12:25:09.517
Link: CVE-2023-5106
JSON object: View
Redhat Information
No data.
CWE