Missing Authorization in GitLab
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 4.4%
from disclosure to weapon0 days
Published on NVDJan 26
metasploitJan 25
exploitation probability
4.4%top 10% of all CVEs
observed exploitation
nono source reports it
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
GitLab · GitLab