2023-11-06 15:00:23 +00:00
{
"id" : "CVE-2023-3399" ,
"sourceIdentifier" : "cve@gitlab.com" ,
"published" : "2023-11-06T13:15:09.503" ,
2023-11-14 19:00:22 +00:00
"lastModified" : "2023-11-14T18:01:40.643" ,
"vulnStatus" : "Analyzed" ,
2023-11-06 15:00:23 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates."
2023-11-07 21:03:21 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se descubri\u00f3 un problema en GitLab EE que afecta a todas las versiones desde 11.6 anteriores a 16.3.6, todas las versiones desde 16.4 anteriores a 16.4.2, todas las versiones desde 16.5 anteriores a 16.5.1. Era posible que un proyecto o miembro de grupo no autorizado leyera las variables CI/CD utilizando las plantillas de proyecto personalizadas."
2023-11-06 15:00:23 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-14 19:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.7 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.1 ,
"impactScore" : 4.0
} ,
2023-11-06 15:00:23 +00:00
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
2023-11-07 21:03:21 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" ,
2023-11-06 15:00:23 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
2023-11-07 21:03:21 +00:00
"scope" : "CHANGED" ,
2023-11-06 15:00:23 +00:00
"confidentialityImpact" : "HIGH" ,
2023-11-07 21:03:21 +00:00
"integrityImpact" : "LOW" ,
2023-11-06 15:00:23 +00:00
"availabilityImpact" : "NONE" ,
2023-11-07 21:03:21 +00:00
"baseScore" : 8.5 ,
"baseSeverity" : "HIGH"
2023-11-06 15:00:23 +00:00
} ,
2023-11-07 21:03:21 +00:00
"exploitabilityScore" : 3.1 ,
"impactScore" : 4.7
2023-11-06 15:00:23 +00:00
}
]
} ,
"weaknesses" : [
2023-11-14 19:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
} ,
2023-11-06 15:00:23 +00:00
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2023-11-14 19:00:22 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "11.6.0" ,
"versionEndExcluding" : "12.9.8" ,
"matchCriteriaId" : "3BA56397-C9B1-4CE4-8FB7-CAB1DD973E02"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "11.6.0" ,
"versionEndExcluding" : "12.9.8" ,
"matchCriteriaId" : "9878DD67-6675-4E1A-A309-A3473D2D0BED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "12.10.0" ,
"versionEndExcluding" : "12.10.7" ,
"matchCriteriaId" : "C9ED9593-9837-4849-A890-C2FDDC56C5A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "12.10.0" ,
"versionEndExcluding" : "12.10.7" ,
"matchCriteriaId" : "846CD4C7-BFCB-4DFC-901E-46CCA8ADA56A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:community:*:*:*" ,
"matchCriteriaId" : "439E1C57-8846-4EB8-A78A-DE6BDAF6CAF5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:13.0.0:*:*:*:enterprise:*:*:*" ,
"matchCriteriaId" : "F6CA871C-BEFF-4951-AC88-ACA603C25CE1"
}
]
}
]
}
] ,
2023-11-06 15:00:23 +00:00
"references" : [
{
"url" : "https://gitlab.com/gitlab-org/gitlab/-/issues/416244" ,
2023-11-14 19:00:22 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Broken Link"
]
2023-11-06 15:00:23 +00:00
} ,
{
"url" : "https://hackerone.com/reports/2021616" ,
2023-11-14 19:00:22 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Permissions Required"
]
2023-11-06 15:00:23 +00:00
}
]
}