CVE-2023-3964: Users can install Composer packages from public projects even when Package registry is turned off
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-3964?
CVE-2023-3964 is a vulnerability in GitLab that allows users to access composer packages on public projects with disabled package registry.
What versions of GitLab are affected by CVE-2023-3964?
GitLab versions starting from 13.2 before 16.4.3, starting from 16.5 before 16.5.3, and starting from 16.6 before 16.6.1 are affected by CVE-2023-3964.
What is the severity of CVE-2023-3964?
CVE-2023-3964 has a severity rating of 4.3, which is considered medium.
How can I fix CVE-2023-3964?
To fix CVE-2023-3964, upgrade GitLab to version 16.4.3, 16.5.3, or 16.6.1 or later.
Where can I find more information about CVE-2023-3964?
You can find more information about CVE-2023-3964 on the GitLab public issue tracker and the HackerOne report linked in the references.