MEDIUM
CVE-2023-5612
CVSS
5.3
Description
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
Summary dbcve.org
GitLab allows users to set email visibility preferences in their profile, but a vulnerability in the tags feed feature permitted unauthorized disclosure of user email addresses even when visibility was disabled. An attacker could access email addresses via the tags feed without authentication or special privileges.
Mitigation
Upgrade GitLab to version 16.6.6, 16.7.4, or 16.8.1 or later to patch the information disclosure vulnerability.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
4.87%
Probability of exploitation in next 30 days
91.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.