LOW
Insertion of Sensitive Information into Log File in GitLab
Published Jul 13, 2023
3.9
LOWCVSS 3.1
EPSS 0.18%
Description
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
Affected products
-
- Version 13.6StatusaffectedConstraints<15.11.10
- Version 16.0StatusaffectedConstraints<16.0.6
- Version 16.1StatusaffectedConstraints<16.1.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 15.11.10, 16.0.6, 16.1.1 or above.
Weaknesses (1)
References (1)
- https://gitlab.com/gitlab-org/gitlab/-/issues/409034 issue-trackingBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/409034 | issue-trackingBroken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jul 13, 2023
Updated Nov 5, 2024
Reserved Jun 22, 2023
Link CVE-2023-3363
CISA Vulnrichment
Updated Nov 5, 2024