MEDIUM

CVE-2023-5612

Gitlab GitLab 2024-01-26 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

Summary dbcve.org

GitLab allows users to set email visibility preferences in their profile, but a vulnerability in the tags feed feature permitted unauthorized disclosure of user email addresses even when visibility was disabled. An attacker could access email addresses via the tags feed without authentication or special privileges.

Mitigation

Upgrade GitLab to version 16.6.6, 16.7.4, or 16.8.1 or later to patch the information disclosure vulnerability.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

4.87%
Probability of exploitation in next 30 days
91.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE