CVE-2023-2478: GitLab
Medium severity, CVSS 6.5. EPSS: 5% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner to any project.
Affected products
- GitLab GitLab: from 15.4.0, before 15.9.7 (fixed in 15.9.7); from 15.10.0, before 15.10.6 (fixed in 15.10.6); from 15.11.0, before 15.11.2 (fixed in 15.11.2)
Published 2023-05-08. Last modified 2026-06-17.