← back
CVE-2023-5612mediumCWE-862

Missing Authorization in GitLab

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 5.3epss 4.4%
from disclosure to weapon0 days
Published on NVDJan 26
metasploitJan 25
exploitation probability
4.4%top 10% of all CVEs
observed exploitation
nono source reports it
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
GitLab · GitLab