CVE-2023-3399: GitLab
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD variables using the custom project templates.
Affected products
- GitLab GitLab: from 11.6.0, before 12.9.8 (fixed in 12.9.8); from 12.10.0, before 12.10.7 (fixed in 12.10.7); version 13.0.0 only
Published 2023-11-06. Last modified 2026-06-17.