CVE-2023-3443: Guest users can react (emojis) on confidential work items which they cant see in a project
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-3443?
CVE-2023-3443 is an improper access control vulnerability in GitLab.
Which versions of GitLab are affected by CVE-2023-3443?
All versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, and all versions starting from 16.6 before 16.6.1 are affected by CVE-2023-3443.
What is the severity of CVE-2023-3443?
CVE-2023-3443 has a severity score of 4.3, which is considered medium.
How can a Guest user exploit CVE-2023-3443?
A Guest user can exploit CVE-2023-3443 by adding an emoji on confidential work items.
Is there a fix available for CVE-2023-3443?
Yes, the fix for CVE-2023-3443 is available in GitLab versions 16.4.3, 16.5.3, and 16.6.1.