Security features bypass in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2023-5512
Published: December 14, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the omission of double encoding in file names which facilitates the creation of repositories with malicious content. A remote user can use specific HTML encoding for file names leading for incorrect representation in the UI.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2023-5512
GitLab Enterprise Edition - addressed in versions 16.4.4, 16.5.4, 16.6.2