CVE-2023-2190 is a medium-severity vulnerability affecting GitLab CE/EE versions 13.10 through 15.11.9, 16.0 through 16.0.5, and 16.1 through 16.1.0. This flaw allows unauthorized users to view new commits to private projects if they forked the project while it was public. With a CVSS score of 6.5, it presents a high confidentiality impact due to information disclosure, though it requires user authentication (PR:L) and has low attack complexity (AC:L). There is no evidence of active exploitation, public exploit code, or significant community discussion beyond a single security release announcement from GitLab.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.10.0, < 15.11.10CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 13.10.0, < 15.11.10CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.0.0, < 16.0.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.0.0, < 16.0.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.1.0, < 16.1.1CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.