Vulnerability CVE-2023-5061


Published: 2023-12-15

Description:
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to override predefined CI variables via the REST API.

 References:
https://gitlab.com/gitlab-org/gitlab/-/issues/425521
https://hackerone.com/reports/2125189

Copyright 2026, cxsecurity.com

 

Back to Top