CVE-2023-4018 is a medium-severity vulnerability affecting GitLab versions 16.2 through 16.2.4 and 16.3 through 16.3.0. It allows unauthorized users to create model experiments in public projects due to improper permission validation. The attack vector is network-based with low complexity, potentially leading to unauthorized data modification (integrity impact). There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one article from GitLab Security acknowledging the fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.2, < 16.2.5CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.3, < 16.3.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.2, < 16.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.2, < 16.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
16.3.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.