An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
References
Link | Resource |
---|---|
https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/ | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/428441 | Broken Link |
https://hackerone.com/reports/2208790 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-26 02:15
Updated : 2024-01-31 20:07
NVD link : CVE-2023-5612
Mitre link : CVE-2023-5612
CVE.ORG link : CVE-2023-5612
JSON object : View
Products Affected
gitlab
- gitlab
CWE