CVE-2023-2478

CVSS V2 None CVSS V3 None
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.
Overview
  • CVE ID
  • CVE-2023-2478
  • Assigner
  • cve@gitlab.com
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-08T21:15:10
  • Last Modified Date
  • 2023-05-08T21:15:10
History
Created Old Value New Value Data Type Notes
2023-05-08 22:00:32 Added to TrackCVE