MEDIUM

CVE-2023-5933

Gitlab GitLab 2024-01-26 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

Summary dbcve.org

Improper input sanitization of usernames in GitLab CE/EE allows authenticated users to make arbitrary API PUT requests. This authorization bypass stems from insufficient validation of user-supplied input in the username field.

Mitigation

Upgrade GitLab to version 16.6.6, 16.7.4, 16.8.1 or later to remediate the input sanitization vulnerability.

Weakness (CWE)

CWE-80
CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.68%
Probability of exploitation in next 30 days
51.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE