SB2023050526 - Security restrictions bypass in GitLab 



SB2023050526 - Security restrictions bypass in GitLab

Published: May 5, 2023

Security Bulletin ID SB2023050526
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-2478)

The vulnerability allows a remote user to compromise any project on the instance.

The vulnerability exists due to improper implementation of access permission. Under certain conditions, any GitLab user account on the instance can use a GraphQL endpoint to attach a malicious runner to any project on the instance.


Remediation

Install update from vendor's website.