CVE-2023-2620
Dashboard / Vulnerabilities / CVE-2023-2620
Summary: Insertion of Sensitive Information Into Sent Data in GitLab
Details: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2620.json, https://nvd.nist.gov/vuln/detail/CVE-2023-2620, https://gitlab.com/gitlab-org/gitlab/-/issues/410433, git://[email protected]:gitlab-org/gitlab.git, https://hackerone.com/reports/1976206
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
