An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
References
Link | Resource |
---|---|
https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/428441 | Broken Link |
https://hackerone.com/reports/2208790 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
31 Jan 2024, 20:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab gitlab
Gitlab |
|
CPE | cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:16.8.0:*:*:*:enterprise:*:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
References | () https://hackerone.com/reports/2208790 - Permissions Required | |
References | () https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ - Vendor Advisory | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/428441 - Broken Link |
26 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-26 02:15
Updated : 2024-10-03 07:15
NVD link : CVE-2023-5612
Mitre link : CVE-2023-5612
JSON object : View
Products Affected
gitlab
- gitlab
CWE