MEDIUM

CVE-2023-5831

Gitlab GitLab 2023-11-06 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.

Summary dbcve.org

A feature flag named `super_sidebar_logged_out` in GitLab CE/EE versions 16.0 through 16.5.1, when enabled, causes the application to disclose GitLab version metadata to unauthenticated/unauthorized users. This information disclosure could aid attackers in identifying vulnerable targets.

Mitigation

Disable the `super_sidebar_logged_out` feature flag if enabled, or upgrade to GitLab versions 16.3.6, 16.4.2, 16.5.1 or later which contain the fix.

Weakness (CWE)

CWE-201

EPSS Score

0.46%
Probability of exploitation in next 30 days
39.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE