CVE-2023-2478
CVSS V2 None
CVSS V3 None
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.
Overview
- CVE ID
- CVE-2023-2478
- Assigner
- cve@gitlab.com
- Vulnerability Status
- Received
- Published Version
- 2023-05-08T21:15:10
- Last Modified Date
- 2023-05-08T21:15:10
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-2478 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2478 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-08 22:00:32 | Added to TrackCVE |