An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk custom email template.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/428268 | Exploit Issue Tracking |
https://hackerone.com/reports/2209702 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
12 Aug 2025, 14:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab gitlab
Gitlab |
|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/428268 - Exploit, Issue Tracking | |
References | () https://hackerone.com/reports/2209702 - Permissions Required | |
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:* |
23 Jun 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Jun 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-20 20:15
Updated : 2025-08-12 14:52
NVD link : CVE-2023-5600
Mitre link : CVE-2023-5600
CVE.ORG link : CVE-2023-5600
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-862
Missing Authorization