CVE-2023-3906

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/09/2023
Last modified:
05/05/2025

Description

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 12.3 (including) 16.2.8 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.3 (including) 16.2.8 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 16.3.0 (including) 16.3.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 16.3.0 (including) 16.3.5 (excluding)
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*