Vulnerability Description
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 12.3, < 16.2.8 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/419213Issue TrackingVendor Advisory
- https://hackerone.com/reports/2071411Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/419213Issue TrackingVendor Advisory
- https://hackerone.com/reports/2071411Permissions Required
FAQ
What is CVE-2023-3906?
CVE-2023-3906 is a vulnerability with a CVSS score of 3.5 (LOW). An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft ...
How severe is CVE-2023-3906?
CVE-2023-3906 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3906?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.