Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44532 | An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy. |
Solution
Upgrade to version 16.2.8, 16.3.5, 16.4.1 or above
Workaround
No workaround given by the vendor.
Tue, 08 Oct 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1333 | NVD-CWE-Other |
Thu, 03 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation in GitLab | Improper Validation of Specified Type of Input in GitLab |
| Weaknesses | CWE-1287 |
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 31 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-22T04:06:58.535Z
Reserved: 2023-07-25T10:30:28.538Z
Link: CVE-2023-3906
Updated: 2024-08-02T07:08:50.669Z
Status : Analyzed
Published: 2023-09-29T07:15:13.233
Modified: 2025-05-05T14:12:08.757
Link: CVE-2023-3906
No data.
OpenCVE Enrichment
No data.
EUVD