cve/2023/CVE-2023-0989.md
2024-05-25 21:48:12 +02:00

843 B

CVE-2023-0989

Description

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD configuration.

POC

Reference

No PoCs from references.

Github