An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "15.2"
},
{
"fixed": "15.9.6"
},
{
"introduced": "15.10"
},
{
"fixed": "15.10.5"
},
{
"introduced": "15.11"
},
{
"fixed": "15.11.1"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "15.2"
},
{
"fixed": "15.9.6"
},
{
"introduced": "15.10"
},
{
"fixed": "15.10.5"
},
{
"introduced": "15.11"
},
{
"fixed": "15.11.1"
}
],
"source": "DESCRIPTION"
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0805.json",
"cna_assigner": "GitLab"
}{
"cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"extracted_events": [
{
"introduced": "15.2"
},
{
"fixed": "15.9.6"
},
{
"introduced": "15.10"
},
{
"fixed": "15.10.5"
},
{
"introduced": "15.11"
},
{
"fixed": "15.11.1"
}
],
"source": "CPE_FIELD"
}