CVE-2023-3102 is a sensitive information leak vulnerability in GitLab Enterprise Edition (EE) affecting versions 16.0 prior to 16.0.6 and 16.1 prior to 16.1.1. This flaw allows unauthorized access to the titles of private issues and merge requests. Rated Medium severity with a CVSS score of 5.3, it has a network attack vector and low attack complexity, potentially leading to a limited disclosure of confidential information. There is currently no evidence of active exploitation, nor are public exploit codes like Metasploit or Nuclei available. While community discussion is minimal, it has received some media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, < 16.0.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
16.1.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:16.1.0:*:*:*:enterprise:*:*:* | ||
>= 16.0, < 16.0.6CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.1, < 16.1.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.