LOW
Improper Validation of Specified Type of Input in GitLab
Published Sep 29, 2023
3.5
LOWCVSS 3.1
EPSS 0.57%
Description
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
Affected products
-
Affected
- ≥ 12.3, < 16.2.8
- ≥ 16.3, < 16.3.5
- ≥ 16.4, < 16.4.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 16.2.8, 16.3.5, 16.4.1 or above
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44532 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/419213 issue-trackingIssue TrackingVendor Advisory
- https://hackerone.com/reports/2071411 technical-descriptionexploitpermissions-requiredbroken-linkPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44532 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/419213 | issue-trackingIssue TrackingVendor Advisory | |
| https://hackerone.com/reports/2071411 | technical-descriptionexploitpermissions-requiredbroken-linkPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 29, 2023
Updated Aug 14, 2026
Reserved Jul 25, 2023
Link CVE-2023-3906
CISA Vulnrichment
Updated Aug 30, 2024
Red Hat
No data
GitHub
No data