CVE Vulnerabilities

CVE-2023-1204

Published: May 03, 2023 | Modified: Jan 30, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab10.0 (including)12.9.8 (excluding)
GitlabGitlab12.10 (including)12.10.7 (excluding)
GitlabGitlab13.0 (including)13.0.1 (excluding)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntutrusty*
GitlabUbuntuxenial*

References