Back

LOW

Improper Validation of Specified Type of Input in GitLab

Published Sep 29, 2023

Description

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

Affected products

Remediation

Vendor solution

Upgrade to version 16.2.8, 16.3.5, 16.4.1 or above

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitLab
Published Sep 29, 2023
Updated Aug 14, 2026
Reserved Jul 25, 2023

CISA Vulnrichment

Updated Aug 30, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitLab
Published Sep 29, 2023
Updated Aug 14, 2026

GitHub

No data