Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2023-5612

 

Information disclosure in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2023-5612

Published: January 26, 2024 / Updated: March 6, 2024


Vulnerability identifier: #VU85819
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5612
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can read the user email address via tags feed although the visibility in the user profile has been disabled.


Affected software

Gitlab Community Edition
GitLab Enterprise Edition

How to mitigate CVE-2023-5612

Install updates from vendor's website.

Gitlab Community Edition - addressed in versions 16.5.8, 16.6.6, 16.7.4, 16.8.1
GitLab Enterprise Edition - addressed in versions 16.5.8, 16.6.6, 16.7.4, 16.8.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins