CVE-2023-1098
moderate-risk
Published 2023-04-05
An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.
Do I need to act?
-
0.45% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.8/10
Medium
NETWORK
/ HIGH complexity
Affected Vendors
References (6)
Permissions Required
https://hackerone.com/reports/1784294
Permissions Required
https://hackerone.com/reports/1784294
30
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
10/34 · Low