CVE-2023-3363
published 2023-07-13CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from…
PriorityP413low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.18%
8.3th percentile
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gitlab | < gitlab 15.11.11+ds1-1 (sid) | gitlab 15.11.11+ds1-1 (sid) |
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 13.6 < 15.11.10 | 15.11.10 |
| gitlab | gitlab | >= 16.0 < 16.0.6 | 16.0.6 |
| gitlab | gitlab | >= 16.0.0 < 16.0.6 | 16.0.6 |
| gitlab | gitlab | >= 16.1 < 16.1.1 | 16.1.1 |
| gitlab | gitlab_ce | — | — |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
osv3.8LOW
vendor_debian3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wh2-fff9-4m63: An information disclosure issue in Gitlab CE/EE affecting all versions from 13
ghsa_unreviewed·2023-07-13
CVE-2023-3363 [LOW] CWE-532 GHSA-2wh2-fff9-4m63: An information disclosure issue in Gitlab CE/EE affecting all versions from 13
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
OSV
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13
osv·2023-07-13·CVSS 3.8
CVE-2023-3363 [LOW] CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
GitLab
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versio
vendor_gitlab·2023-07-13·CVSS 3.9
CVE-2023-3363 [LOW] CWE-532 CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versio
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
Debian
CVE-2023-3363: gitlab - An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6...
vendor_debian·2023·CVSS 3.9
CVE-2023-3363 [LOW] CVE-2023-3363: gitlab - An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6...
An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.
Scope: local
sid: resolved (fixed in 15.11.11+ds1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-13
Published