← Back to browse · API

CVE-2023-5009

Severity
CRITICAL
CVSS
9.6
EPSS
0.08263
Risk score
41.29
CISA KEV
No
PoC
No
Published
2023-09-19
Modified
2026-05-02
First seen
2026-08-07
Aliases
EUVD-2023-57355, GHSA-G4C2-HHJC-4HGG
Products
GitLab:GitLab 13.12 <16.2.7, GitLab:GitLab 16.3 <16.3.4
Sources
euvd EUVD-2023-57355

Description

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.

References