PT-2024-1472 · Gitlab · Gitlab

Erruqill

·

Published

2024-01-25

·

Updated

2024-10-03

·

CVE-2023-5612

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 16.6.6 GitLab versions 16.7 prior to 16.7.4 GitLab versions 16.8 prior to 16.8.1
Description An issue has been discovered in GitLab that allows reading the user email address via tags feed, even though the visibility in the user profile has been disabled. This issue is related to information disclosure. Exploitation of this issue may allow a remote attacker to access confidential data.
Recommendations For versions prior to 16.6.6, update to version 16.6.6 or later. For versions 16.7 prior to 16.7.4, update to version 16.7.4 or later. For versions 16.8 prior to 16.8.1, update to version 16.8.1 or later.

Exploit

Fix

Information Disclosure

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-00978
BIT-GITLAB-2023-5612
CVE-2023-5612

Affected Products

Gitlab