此页面尚未翻译为您的语言。我们正在努力翻译,目前显示英文内容。

💡 Keep dependencies up to date — most exploits target known, patchable vulnerabilities.

MEDIUMCVE-2026-3160CVSS 5.8

CVE-2026-3160: Information Disclosure in GitLab

平台

gitlab

组件

gitlab

修复版本

18.11.3

正在翻译为您的语言…

CVE-2026-3160 describes an information disclosure vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw allows authenticated users to view Jira issues that fall outside the intended project scope, effectively bypassing access controls. The vulnerability impacts versions 13.7.0 through 18.11.3, and a fix is available in version 18.11.3.

影响与攻击场景翻译中…

The primary impact of CVE-2026-3160 is unauthorized access to Jira issue data. An attacker, already authenticated within GitLab, could leverage this vulnerability to view Jira issues associated with other projects or teams they are not explicitly authorized to access. This could expose sensitive information such as bug reports, feature requests, or internal discussions. The blast radius is limited to the Jira integration within GitLab; however, the potential for data leakage remains significant, particularly in organizations where Jira is used to manage critical project information. This vulnerability highlights the importance of proper access control enforcement within integrated systems.

利用背景翻译中…

CVE-2026-3160 was published on May 14, 2026. Its severity is currently assessed as medium. No public proof-of-concept (POC) code has been released as of this writing. There are no indications of active exploitation campaigns targeting this vulnerability. The vulnerability is not currently listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog.

威胁情报

漏洞利用状态

概念验证未知
CISA KEVNO
互联网暴露

CISA SSVC

利用情况none
可自动化yes
技术影响partial

CVSS 向量

威胁情报· CVSS 3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N5.8MEDIUMAttack VectorNetwork攻击者如何到达目标Attack ComplexityLow利用漏洞所需的条件Privileges RequiredNone攻击所需的认证级别User InteractionNone是否需要受害者采取行动ScopeChanged超出受影响组件的影响范围ConfidentialityLow敏感数据泄露风险IntegrityNone数据未授权篡改风险AvailabilityNone服务中断风险nextguardhq.com · CVSS v3.1 基础分数
这些指标意味着什么?
Attack Vector
网络 — 可通过互联网远程利用,无需物理或本地访问。攻击面最大。
Attack Complexity
低 — 无需特殊条件,可以稳定地利用漏洞。
Privileges Required
无 — 无需认证,无需凭证即可利用。
User Interaction
无 — 攻击自动且无声,受害者无需任何操作。
Scope
已改变 — 攻击可以超出脆弱组件,影响其他系统。
Confidentiality
低 — 可访问部分数据。
Integrity
无 — 无完整性影响。
Availability
无 — 无可用性影响。

受影响的软件

组件gitlab
供应商GitLab
最低版本13.7.0
最高版本18.11.3
修复版本18.11.3

弱点分类 (CWE)

时间线

  1. 已保留
  2. 发布日期

缓解措施和替代方案翻译中…

The recommended mitigation for CVE-2026-3160 is to immediately upgrade GitLab to version 18.11.3 or later. If upgrading is not immediately feasible, consider temporarily disabling the Jira integration until the upgrade can be performed. Review existing Jira integration configurations to ensure that access controls are properly enforced at the Jira level. While a WAF or proxy cannot directly prevent this vulnerability, they can be configured to monitor for unusual Jira access patterns that might indicate exploitation. After upgrading, verify the fix by attempting to access Jira issues outside the expected project scope; access should be denied.

修复方法翻译中…

Actualice GitLab a la versión 18.9.7 o superior, 18.10.6 o superior, o 18.11.3 o superior para mitigar la vulnerabilidad. Esta actualización corrige un problema de 'Confused Deputy' que permitía a usuarios autenticados acceder a información de Jira fuera del alcance del proyecto configurado.

常见问题翻译中…

What is CVE-2026-3160 — Information Disclosure in GitLab?

CVE-2026-3160 is a medium severity vulnerability in GitLab affecting versions 13.7.0–18.11.3. It allows authenticated users to view Jira issues outside the configured project scope, bypassing access controls.

Am I affected by CVE-2026-3160 in GitLab?

You are affected if you are running GitLab CE or EE versions 13.7.0 through 18.11.3. Versions prior to 18.11.3 are vulnerable to information disclosure.

How do I fix CVE-2026-3160 in GitLab?

Upgrade GitLab to version 18.11.3 or later to remediate the vulnerability. If immediate upgrade is not possible, temporarily disable the Jira integration.

Is CVE-2026-3160 being actively exploited?

As of the current assessment, there are no indications of active exploitation campaigns targeting CVE-2026-3160.

Where can I find the official GitLab advisory for CVE-2026-3160?

Refer to the official GitLab security advisory for CVE-2026-3160 on the GitLab website: [https://gitlab.com/security/advisories/CVE-2026-3160](https://gitlab.com/security/advisories/CVE-2026-3160)

你的项目受影响吗?

上传你的依赖文件,立即了解此CVE和其他CVE是否影响你。

live免费扫描

立即试用 — 无需账户

上传任何清单文件 (composer.lock, package-lock.json, WordPress 插件列表…) 或粘贴您的组件列表。您立即获得一份漏洞报告。上传文件只是开始:拥有账户后,您将获得持续监控、Slack/电子邮件警报、多项目和白标报告。

手动扫描Slack/邮件提醒持续监控白标报告

拖放您的依赖文件

composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...