CVE-2023-3906 — Improper Validation of Specified Type of Input in Gitlab
Severity
3.5LOWNVD
EPSS
0.3%
top 51.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Description
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-x2v6-6q9m-6qx9: An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12↗2023-09-29
📋Vendor Advisories
2GitLab▶
CVE-2023-3906: An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 1↗2023-09-29
Debian▶
CVE-2023-3906: gitlab - An input validation issue in the asset proxy in GitLab EE, affecting all version...↗2023