216.73.216.226

CVE-2023-5009

· Published 19/09/2023 10:16 · Modified 21/12/2025 07:45 · Author: The MITRE Corporation

Labels: CVE-2023-5009

Essential information

Published
19/09/2023 10:16
Modified
21/12/2025 07:45
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:N

CVSS metrics

Description

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

NVD status

NVD
View on NVD