CVE-2023-3363Log File Information Exposure in Gitlab

Severity
3.8LOWNVD
EPSS
0.0%
top 94.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13

Description

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook tokens when the log format was set to `default`.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 2.0 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab16.016.0.6
NVDgitlab/gitlab13.615.11.10+2
debiandebian/gitlab< gitlab 15.11.11+ds1-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-2wh2-fff9-4m63: An information disclosure issue in Gitlab CE/EE affecting all versions from 132023-07-13
OSV
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 132023-07-13

📋Vendor Advisories

2
GitLab
CVE-2023-3363: An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versio2023-07-13
Debian
CVE-2023-3363: gitlab - An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6...2023