{"api_version":"1","generated_at":"2026-07-23T10:06:07+00:00","cve":"CVE-2023-1071","urls":{"html":"https://cve.report/CVE-2023-1071","api":"https://cve.report/api/cve/CVE-2023-1071.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1071","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1071"},"summary":{"title":"CVE-2023-1071","description":"An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic.","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2023-04-05 21:15:00","updated_at":"2023-04-12 19:23:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","refsource":"MISC","tags":[],"title":"Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","refsource":"CONFIRM","tags":[],"title":"2023/CVE-2023-1071.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1071","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1071","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This vulnerability has been discovered internally by GitLab team.","lang":""}],"nvd_cpes":[{"cve_year":"2023","cve_id":"1071","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1071","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1071","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1071","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"15.10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-1071","qid":"378330","title":"GitLab Multiple Security Vulnerability"},{"cve":"CVE-2023-1071","qid":"691107","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (54006796-cf7b-11ed-a5d5-001b217b3468)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2023-1071","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=15.5, <15.8.5"},{"version_value":">=15.9, <15.9.4"},{"version_value":">=15.10, <15.10.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Uncontrolled resource consumption in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/385434","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1071.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue from an epic."}]},"impact":{"cvss":{"vectorString":"AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":3,"baseSeverity":"LOW"}},"credit":[{"lang":"eng","value":"This vulnerability has been discovered internally by GitLab team."}]},"nvd":{"publishedDate":"2023-04-05 21:15:00","lastModifiedDate":"2023-04-12 19:23:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:15.10.0:*:*:*:community:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.9.0","versionEndExcluding":"15.9.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.8.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.5.0","versionEndExcluding":"15.8.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}