CVE-2023-1098 is an information disclosure vulnerability in GitLab EE/CE, impacting versions 11.5 through 15.8.4, 15.9 through 15.9.3, and 15.10.0. This flaw allows an authenticated administrator to leak passwords from repository mirror configurations. Rated Medium with a CVSS score of 4.9, it requires high privileges (PR:H) and has a high confidentiality impact (C:H) over the network (AV:N). There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond the vendor's security release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.5.0, < 15.8.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.5.0, < 15.8.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.9.0, < 15.9.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.9.0, < 15.9.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
15.10.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.