Description
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 16.8.1, 16.7.4, 16.6.6 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58205 | An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests. |
References
History
Wed, 13 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-20T04:10:58.262Z
Reserved: 2023-11-02T15:01:52.148Z
Link: CVE-2023-5933
Updated: 2024-08-02T08:14:25.134Z
Status : Modified
Published: 2024-01-26T01:15:08.660
Modified: 2024-11-21T08:42:48.527
Link: CVE-2023-5933
No data.
OpenCVE Enrichment
No data.
EUVD