An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2024-01-26T01:02:58.931Z

Updated: 2024-01-26T01:02:58.931Z

Reserved: 2023-11-02T15:01:52.148Z


Link: CVE-2023-5933

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-26T01:15:08.660

Modified: 2024-01-31T20:31:37.367


Link: CVE-2023-5933

JSON object: View

cve-icon Redhat Information

No data.