An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44030 | An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`. |
Fixes
Solution
Upgrade to versions 15.11.10, 16.0.6, 16.1.1 or above.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/409034 |
|
History
Tue, 05 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-11-05T15:14:10.202Z
Reserved: 2023-06-22T01:14:48.593Z
Link: CVE-2023-3363
Updated: 2024-08-02T06:55:02.594Z
Status : Modified
Published: 2023-07-13T03:15:10.280
Modified: 2024-11-21T08:17:06.270
Link: CVE-2023-3363
No data.
OpenCVE Enrichment
No data.
EUVD