An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
References
Link | Resource |
---|---|
https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/428441 | Broken Link |
https://hackerone.com/reports/2208790 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
03 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 |
31 Jan 2024, 20:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab
Gitlab gitlab |
|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/428441 - Broken Link | |
References | () https://hackerone.com/reports/2208790 - Permissions Required | |
References | () https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ - Vendor Advisory |
26 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-26 02:15
Updated : 2024-10-03 07:15
NVD link : CVE-2023-5612
Mitre link : CVE-2023-5612
CVE.ORG link : CVE-2023-5612
JSON object : View
Products Affected
gitlab
- gitlab
CWE