An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24027 | An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to an unauthorized user at project export. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-668 | NVD-CWE-Other |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insertion of Sensitive Information Into Sent Data in GitLab | |
| Weaknesses | CWE-201 |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-01-07T16:56:43.350Z
Reserved: 2023-04-04T00:00:00
Link: CVE-2023-1825
Updated: 2024-08-02T06:05:26.652Z
Status : Analyzed
Published: 2023-06-07T17:15:09.900
Modified: 2025-03-20T17:00:56.707
Link: CVE-2023-1825
No data.
OpenCVE Enrichment
No data.
EUVD