MEDIUM
CVE-2023-5933
CVSS
5.4
Description
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
Summary dbcve.org
Improper input sanitization of usernames in GitLab CE/EE allows authenticated users to make arbitrary API PUT requests. This authorization bypass stems from insufficient validation of user-supplied input in the username field.
Mitigation
Upgrade GitLab to version 16.6.6, 16.7.4, 16.8.1 or later to remediate the input sanitization vulnerability.
Weakness (CWE)
CWE-80
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.68%
Probability of exploitation in next 30 days
51.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.