CVE Vulnerabilities

CVE-2023-1204

Published: May 03, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 10.0 (including) 12.9.8 (excluding)
Gitlab Gitlab 12.10 (including) 12.10.7 (excluding)
Gitlab Gitlab 13.0 (including) 13.0.1 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu trusty *
Gitlab Ubuntu xenial *

References