VulnerabilityModified
CVE-2023-5612
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.
MEDIUM 5.3EPSS 4.87%
Does this matter?
Lower severity and a low EPSS score (4.87%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 4.87% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/428441Broken Link
- https://hackerone.com/reports/2208790Permissions Required
- https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/428441Broken Link
- https://hackerone.com/reports/2208790Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.