<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:37:42 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2023-3915 — Incorrect Execution-Assigned Permissions in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3915</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0707 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;GitLab&lt;/span&gt;. Certaines d'entre elles permet…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0707</link>
      <description>certfr-2023-avi-0707</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0707</guid>
    </item>
    <item>
      <title>EUVD-2026-317881</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317881</link>
      <description>EUVD-2026-317881</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317881</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3915</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3915</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3915</guid>
    </item>
    <item>
      <title>GHSA-3m8p-28cp-6cg5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3m8p-28cp-6cg5</link>
      <description>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3m8p-28cp-6cg5</guid>
    </item>
    <item>
      <title>gsd-2023-3915</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3915</link>
      <description>gsd-2023-3915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3915</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2244 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2244</link>
      <description>&lt;p&gt;Ein entfernter, authentifizierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um8 Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentifizierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um8 Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2244</guid>
    </item>
  </channel>
</rss>
