CVE-2023-3950 PUBLISHED

An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the key, not read it.

EPSS 0.05% · 14.2th percentile

Risk Scores

EPSS Score
0.05%
14.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab16.2.0, 16.3.0
Bitnamigitlab16.2.0, 16.3.0

Timeline

References

Open in Interactive Console →