CVE-2023-3906Improper Validation of Specified Type of Input in Gitlab

Severity
3.5LOWNVD
EPSS
0.3%
top 51.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29

Description

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab16.316.3.5+1
NVDgitlab/gitlab12.316.2.8+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-x2v6-6q9m-6qx9: An input validation issue in the asset proxy in GitLab EE, affecting all versions from 122023-09-29

📋Vendor Advisories

2
GitLab
CVE-2023-3906: An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 12023-09-29
Debian
CVE-2023-3906: gitlab - An input validation issue in the asset proxy in GitLab EE, affecting all version...2023