CVE-2023-5831
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.
Summary dbcve.org
A feature flag named `super_sidebar_logged_out` in GitLab CE/EE versions 16.0 through 16.5.1, when enabled, causes the application to disclose GitLab version metadata to unauthenticated/unauthorized users. This information disclosure could aid attackers in identifying vulnerable targets.
Mitigation
Disable the `super_sidebar_logged_out` feature flag if enabled, or upgrade to GitLab versions 16.3.6, 16.4.2, 16.5.1 or later which contain the fix.