← Back to browse · API

CVE-2023-2478

Severity
CRITICAL
CVSS
9.6
EPSS
0.05042
Risk score
40.16
CISA KEV
No
PoC
No
Published
2023-05-08
Modified
2025-01-29
First seen
2026-08-07
Aliases
EUVD-2023-33963, GHSA-7H3W-V9HH-HP55
Products
GitLab:GitLab 15.10, <15.10.6, GitLab:GitLab 15.11, <15.11.2, GitLab:GitLab 15.4, <15.9.7
Sources
euvd EUVD-2023-33963

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.

References